Particle.news
Download on the App Store

Attackers Forge Admin Tokens Using Critical JFrog Artifactory Flaw

An authentication bypass that lets unauthenticated actors gain administrative control of Artifactory repositories creates urgent software supply‑chain risk.

Overview

  • JFrog released patches for CVE-2026-82329 on August 28 and said its cloud instances were already updated while self-hosted customers must apply listed patched versions.
  • Security researchers at watchTowr reported on September 1 that attackers are exploiting the flaw to mint administrator tokens and to enumerate users, groups, credentials and federated access topologies.
  • The bug arises in Artifactory’s access component and can appear in default configurations that yield a forged join key, allowing attackers to obtain admin privileges without authentication.
  • Attackers with admin access can read or replace stored binaries, containers and models so downstream build and deployment systems could automatically pull poisoned artifacts.
  • Organizations are urged to patch self-managed instances, rotate exposed credentials, inspect Artifactory audit logs for suspicious token issuance, and review connected systems for backdoors while investigations continue.