Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited to mint administrative tokens on self-managed instances. Because Artifactory artifacts are trusted by downstream build and deployment systems, attackers could poison packages and potentially trigger malicious code execution across connected environments. #CVE-2026-82329 #JFrogArtifactory #watchTowr #GuillermoRauch

Keypoints

  • CVE-2026-82329 enables authentication bypass in default Artifactory deployments.
  • Attackers can create admin tokens without authentication.
  • watchTowr observed active exploitation in the wild.
  • Compromised access can expose users, groups, artifacts, and security settings.
  • JFrog released fixes in multiple Artifactory versions on August 28.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/