Overview
- JFrog released patches for CVE-2026-82329 on August 28 and said its cloud instances were already updated while self-hosted customers must apply listed patched versions.
- Security researchers at watchTowr reported on September 1 that attackers are exploiting the flaw to mint administrator tokens and to enumerate users, groups, credentials and federated access topologies.
- The bug arises in Artifactory’s access component and can appear in default configurations that yield a forged join key, allowing attackers to obtain admin privileges without authentication.
- Attackers with admin access can read or replace stored binaries, containers and models so downstream build and deployment systems could automatically pull poisoned artifacts.
- Organizations are urged to patch self-managed instances, rotate exposed credentials, inspect Artifactory audit logs for suspicious token issuance, and review connected systems for backdoors while investigations continue.