Hackers Exploit Critical JFrog Artifactory Flaw to Forge Administrative Tokens
A critical authentication bypass vulnerability, tracked as CVE-2026-82329, is being exploited to create forged JFrog Artifactory tokens that grant administrative access.
The vulnerability affects the default configuration of self-managed JFrog Artifactory instances. Artifactory is a repository manager used by organizations to store, organize, secure, and distribute software packages and other development artifacts.
An unauthenticated attacker who gains access to the targeted network can exploit the flaw to obtain administrative privileges without valid credentials.
Researchers at offensive security firm watchTowr said they observed attackers exploiting the vulnerability by “minting admin tokens themselves.”
JFrog has released limited technical information about the vulnerability. According to the company’s security advisory, the flaw is exploitable when Artifactory is running with its default settings.
Vercel CEO Guillermo Rauch warned that the impact could extend beyond the compromised Artifactory server because trusted packages may be consumed automatically by downstream systems.
“Administrative access to Artifactory reaches released artifacts that downstream systems already trust and automatically pull,” Collin Hogue-Spears, senior director of solution management at application security firm Black Duck, told BleepingComputer.
Hogue-Spears also noted that JFrog access tokens function as independent credentials with their own expiration and revocation controls. As a result, upgrading Artifactory binaries alone may not invalidate tokens that attackers have already created.
Organizations commonly use JFrog Artifactory to host binaries and software packages consumed by build and deployment systems. An attacker with administrative access could therefore replace trusted artifacts with malicious versions, potentially leading to code execution on downstream developer, build, or production systems.
Rauch also speculated that the vulnerability could be connected to recent research involving autonomous artificial intelligence agents, although no technical evidence confirming that connection has been provided.
JFrog addressed the issue on August 28 in Artifactory versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20, according to the vendor’s CVE-2026-82329 advisory. JFrog said its cloud environment is already protected.
By forging an administrator token, an attacker could enumerate users, groups, and federation topology; read stored artifacts; modify security settings; and tamper with existing software packages.
It remains unclear how widespread the exploitation is or whether attackers successfully compromised any Artifactory servers. JFrog has not publicly released the number of affected organizations, detailed telemetry, or indicators of compromise (IoCs).
BleepingComputer contacted JFrog for additional information about the reported attacks but had not received a response at the time of publication.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



.png)
