Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
A critical vulnerability in JFrog Artifactory, patched just days after its disclosure, is being actively exploited by threat actors to gain administrative access. This allows attackers to poison build pipelines and escalate privileges, potentially leading to widespread damage within software supply chains. The vulnerability allows for easy generation of admin tokens and enumeration of user data.
A critical security flaw in JFrog Artifactory is being exploited in the wild, according to watchTowr. The vulnerability, identified as CVE-2026-82329 (CVSS score: 9.8), is an authentication bypass that can lead to administrative access in Artifactory, even with default configurations and no user interaction required.
JFrog released Artifactory version 7.161.20 on August 28, 2026, to address the issue, which affects the following versions:
- 7.161.0 > 7.161.19
- 7.146.0 > 7.146.36
- 7.133.0 > 7.133.28
- 7.125.0 > 7.125.19
- 7.117.0 > 7.117.27
- 7.111.4 > 7.111.21
Threat actors have begun weaponizing the flaw since September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies. Vercel CEO Guillermo Rauch highlighted the potential impact, stating that Artifactory hosts binaries, allowing attackers to poison build pipelines and move laterally into production systems.
Organizations running self-managed versions of JFrog Artifactory are advised to apply patches to internet-exposed systems immediately, as well as inspect audit logs, rotate exposed credentials, and review connected systems for malicious changes or backdoor access.
