Skip to content

Build2 publishers2 min readPublished

Attackers chain three JFrog Artifactory flaws to mint their own admin tokens

Attackers are chaining three self-hosted JFrog Artifactory flaws, one rated CVSS 9.8, to mint administrator tokens in under five minutes. Because every build resolves its packages through that one repository, it is as efficient to attack as to run.

The Engineer · Build desk

Illustration accompanying Attackers chain three JFrog Artifactory flaws to mint their own admin tokens

What happened

  • CVE-2026-82329, rated critical, lets an unauthenticated attacker obtain administrative control on its own, without touching the other two flaws.
  • The chain's first link, CVE-2026-42018, hands an anonymous user token to an unauthenticated caller even on instances where anonymous access has been disabled.
  • After gaining admin, intruders created persistent administrator accounts, deployed malicious Groovy plugins to run code, harvested Access signing keys, and left anti-forensics measures behind.
  • Fixes shipped between late July and late August, exploitation was seen from mid-August, and instances that had not upgraded stayed exposed for weeks.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure An attacker holding the repository can swap cached packages and abuse stored publishing credentials, so the compromise reaches builds that never touched the vulnerable server.
  • decision Every token issued before the upgrade has to be treated as compromised and rotated, and administrator accounts and their attached SSH keys audited for unfamiliar entries.
  • constraint Suspect plugins and accounts should be disabled and preserved, not deleted, because attribution and scope assessment depend on artifacts a cleanup destroys.
  • contradiction The two write-ups name different fixed builds for the 7.133 branch, 7.133.11 and 7.133.29, so confirm the branch-to-version mapping against JFrog's advisory before upgrading.

The chain of the two lesser flaws is a few HTTP calls. An unauthenticated POST to /access/api/v1/aws/token/ with a trailing slash returns HTTP 200 and a JWT for the internal anonymous user, CVE-2026-42018 [16]. That token is exchanged at POST /access/api/v1/tokens for one carrying admin authority, using the scope-validation weakness CVE-2026-42016 [16][5]. The escalated token keeps the anonymous username, so the administrative requests that follow appear in the logs with an actor of token:anonymous [17]. Audit only for unfamiliar usernames and you will miss it.

CVE-2026-82329 works differently. In a default JFrog Access install the trusted set includes an empty-string join key, which leaves the signing key for that entry fully known, so an attacker can forge a cluster join token and mint a platform administrator token [2]. watchTowr reported attackers minting administrator tokens for themselves and then enumerating users, groups, credential sets and federation topology [3].

Wiz.io, which disclosed the flaws, said: "These CVEs are trivial to exploit, a handful of unauthenticated HTTP requests. If your instance was exposed while vulnerable, assume compromise and hunt for post-exploitation artifacts. Upgrading closes the door but does not evict an attacker who is already inside" [13][14].

Erik York, a cybersecurity specialist, wrote on LinkedIn: "Artifactory sits at the center of a LOT of software supply chains. This is exactly the kind of bug that turns into next year's SolarWinds story if it's not patched fast" [19]. Jim Nitterauer, senior director of information security at Graylog, said: "Because Artifactory sits at the heart of software build pipelines, a compromise is a direct supply-chain risk and patch adoption has lagged badly, with attacks observed within four days of disclosure of the third bug" [20].

A fix only helps the instances that install it, so the durable controls are the ones that do not depend on upgrade timing: immutable artifacts, signed releases verified at deploy time, separation between the repository management plane and the build network, and least-privilege tokens that cannot be escalated [12].

What to watch

  • Whether CISA adds the three CVEs to its Known Exploited Vulnerabilities catalog and sets a federal patch deadline.
  • Any confirmed downstream tampering traced to a compromised instance, such as replaced cached packages or abused publishing credentials.
  • Whether JFrog or Wiz publishes fuller indicators of compromise beyond the token:anonymous log actor and malicious Groovy plugins.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories