Critical Vulnerability in JFrog Artifactory Exploited to Mint Admin Tokens
- akidh2
- 21 hours ago
- 1 min read

In late August 2026, security researchers warned that threat actors began actively exploiting a newly disclosed critical security vulnerability in JFrog Artifactory. Tracked as CVE-2026-82329 with a maximum CVSS severity score of 9.8, the flaw allows unauthenticated attackers with network access to bypass authentication and gain full administrative privileges on vulnerable self-hosted instances under default configurations.
Exploitation Dynamics and Attacker Activity
Security telemetry revealed that real-world exploitation began merely days after the public patch disclosure. Threat actors are weaponizing the flaw to automatically generate administrative tokens, enumerate user accounts, dump credential sets, and map federated access topologies. By obtaining administrative control over a central software repository like Artifactory, attackers gain the ability to compromise build pipelines, modify production software artifacts, and execute software supply chain attacks downstream.
Impact and Remediation Guidance
The vulnerability exclusively impacts self-hosted deployments running specific versions of Artifactory across multiple legacy and current release streams. Cloud-hosted SaaS instances were confirmed protected. JFrog released security updates in Artifactory version 7.161.20 to remediate the issue. Security teams running self-hosted instances are urged to immediately apply the vendor patches, audit system access logs for unauthorized token creation, rotate potentially exposed environment credentials, and inspect connected continuous integration pipelines for malicious modifications.




Comments