Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, just days after JFrog released a patch in version 7.161.20. The flaw affects default configurations and can let unauthenticated attackers gain administrative access, enabling token theft, user enumeration, and potential supply chain compromise. #JFrogArtifactory #CVE2026-82329 #JFrogAccess

Keypoints

  • CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory.
  • JFrog patched the flaw in Artifactory version 7.161.20 on August 28, 2026.
  • The issue affects several 7.x release ranges and works in default configurations without authentication.
  • Attackers are already weaponizing the bug to mint admin tokens and enumerate users, groups, and credentials.
  • Organizations should patch exposed systems, inspect logs, rotate credentials, and check for malicious changes.

Read More: https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html