JFrog Artifactory is getting hammered: admin tokens without a password
Vulnerability Management

JFrog Artifactory is getting hammered: admin tokens without a password

Mathew Potter

Security Analyst

September 13, 2026

Your build pipeline trusts Artifactory for jars, containers, and deploy keys. Attackers noticed. September brought confirmed in-the-wild exploitation against self-hosted JFrog Artifactory, including a CVSS 9.8 authentication bypass that mints administrative access tokens with a single unauthenticated HTTP request.

How the attacks actually work

CVE-2026-82329 is the headline: under default configuration, a remote attacker can POST to /access/api/v1/registry/join and receive HTTP 201 with an admin-scoped token in the response. Fastly logged exploitation climbing from scattered probes to more than 400,000 attempts in a single day after public exploit code appeared.

Wiz Research separately documented attackers chaining CVE-2026-42018 and CVE-2026-42016 to escalate a low-privilege anonymous token to full admin scope. Post-exploitation looks like real operator work: new persistent admin users, Groovy plugins for code execution, configuration exfiltration, SSH keys glued onto created accounts, and custom Rust backdoors for command and control.

CISA added the Artifactory flaws to KEV with federal remediation dates in September. JFrog Cloud was patched automatically. Self-managed installs are where the pain concentrates.

Why DevOps teams underestimate this

Artifactory often sits behind a VPN in documentation and on the public internet in reality. It holds secrets that never made it to a proper vault. Compromise there is a supply-chain event: malicious artifacts ship downstream, CI variables leak, and defenders chase endpoint alerts while the root cause lives in the repo server.

Industry stats quoted in The Register suggested many organizations remained on vulnerable builds weeks after disclosure. Patch velocity for developer tooling still lags ERP and email by a full quarter in most environments we review.

What we would do this week

  • Upgrade to a fixed branch version: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 as appropriate.
  • Hunt for POSTs to the registry join endpoint since late August. HTTP 201 from an unknown source is a smoking gun.
  • Audit admin users, API tokens, and Groovy plugins added in the past 30 days.
  • Rotate join keys and revoke long-lived tokens if you cannot prove cleanliness.
  • Stop exposing Artifactory to the open internet without WAF, MFA, and aggressive logging.

Bottom line

Artifact servers are production systems even when only developers log in. Forensic Five helps Canadian organizations map external exposure, review CI and registry configuration, and produce evidence for insurers and clients. We are based in St. Albert, Alberta. Scoped work, no vendor partnerships muddying the report.

Tags

JFrog Artifactory supply chain CVE-2026-82329 devops

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.