Particle.news

Attackers Forge Admin Tokens Using Critical JFrog Artifactory Flaw

An authentication bypass that lets unauthenticated actors gain administrative control of Artifactory repositories creates urgent software supply‑chain risk.

Overview

  • JFrog released patches for CVE-2026-82329 on August 28 and said its cloud instances were already updated while self-hosted customers must apply listed patched versions.
  • Security researchers at watchTowr reported on September 1 that attackers are exploiting the flaw to mint administrator tokens and to enumerate users, groups, credentials and federated access topologies.
  • The bug arises in Artifactory’s access component and can appear in default configurations that yield a forged join key, allowing attackers to obtain admin privileges without authentication.
  • Attackers with admin access can read or replace stored binaries, containers and models so downstream build and deployment systems could automatically pull poisoned artifacts.
  • Organizations are urged to patch self-managed instances, rotate exposed credentials, inspect Artifactory audit logs for suspicious token issuance, and review connected systems for backdoors while investigations continue.