Zero Day Room
Live
Vulnerabilities

Critical JFrog Artifactory Flaw Exploited

Threat actors are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, to mint administrator tokens.

Threat actors are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, to mint administrator...

Attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory to gain administrative privileges. The flaw, tracked as CVE-2026-82329 with a CVSS score of 9.8, was patched by JFrog on August 28, 2026, but exploitation began just days later.

According to cybersecurity firm watchTowr, the vulnerability allows an unauthenticated attacker with network access to obtain administrative control over an Artifactory instance. The issue resides in the JFrog Access component, which handles credential issuance and validation.

Vulnerability Details and Affected Versions

The vulnerability affects default configurations and requires no authentication or user interaction. Yordan Ganchev, principal threat intelligence specialist at watchTowr, explained that instances without an additional join key configured receive a phantom join key. Attackers can abuse this to forge access and create administrator-level credentials.

JFrog patched the flaw in Artifactory version 7.161.20. The following versions are vulnerable:

Version Range StartVersion Range End
7.161.07.161.19
7.146.07.146.36
7.133.07.133.28
7.125.07.125.19
7.117.07.117.27
7.111.47.111.21

Vercel CEO Guillermo Rauch described the flaw as an RCE bomb because Artifactory hosts binaries, allowing an attacker to poison everything. He warned that admin escalation could cause damage beyond that.

Active Exploitation and Campaign Impact

WatchTowr reports that threat actors began weaponizing CVE-2026-82329 on September 1, 2026. They are using it to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies.

Ganchev stated that this moved from disclosure to real-world exploitation with uncomfortable efficiency. He added that anyone following along knows what comes next: things will get worse.

Gaining admin access to a central software supply chain system like Artifactory grants significant power. Attackers can then tamper with build pipelines, move laterally into production systems, and potentially push malicious changes downstream to customers. They can build, ship, and distribute software rapidly, mimicking legitimate engineering workflows.

Mitigation and Response Recommendations

Organizations running self-managed JFrog Artifactory are urged to apply patches to internet-exposed systems immediately. The primary action is to upgrade to version 7.161.20 or later.

Beyond patching, watchTowr recommends inspecting audit logs for suspicious activity, rotating any credentials that may have been exposed, and thoroughly reviewing connected systems for signs of malicious changes or backdoor access. Continuous monitoring is critical.

The swift transition from patch release to active exploitation highlights the urgency for administrators. This critical vulnerability demands immediate attention to prevent severe compromise of software supply chains.

Related coverage

More from Vulnerabilities