Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
Attackers are actively exploiting a critical authentication bypass vulnerability, tracked as CVE-2026-82329, in self-managed JFrog Artifactory instances. This flaw exists within the default configuration and permits unauthenticated network attackers to forge administrative tokens, granting them full control over the repository manager.
The compromise allows adversaries to tamper with trusted software artifacts, potentially injecting malicious code into downstream build and deployment systems that automatically pull packages from Artifactory. Because issued tokens remain valid even after binary upgrades, organizations must revoke existing credentials alongside applying patches. JFrog resolved the issue on August 28 in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.