Skip to content
Artifactory flaws give attackers a five-minute path to administrator access

Artifactory flaws give attackers a five-minute path to administrator access

News.Lavx.Hu • September 28, 2026

Attackers are chaining three JFrog Artifactory vulnerabilities against Internet-accessible, self-hosted deployments to bypass authentication, escalate token privileges and plant persistence. Teams must patch fixed release branches and investigate exposed systems for new accounts, plugins and stolen keys.

Attackers are chaining three vulnerabilities in self-hosted JFrog Artifactory to bypass authentication and gain administrator access in under five minutes, according to Wiz Research . The activity puts software build pipelines, package repositories and downstream customers at risk.

Artifactory stores the binaries, packages and credentials that software teams use to build and release applications. An intruder with administrative control can alter artifacts, steal credentials, create durable access and use the registry as a path into connected systems.

Three flaws form an attack path

The vulnerabilities carry two high-severity ratings and one critical rating:

CVE-2026-42018: Artifactory may return a JWT for its internal anonymous user to an unauthenticated requester, even when administrators disable anonymous access.

CVE-2026-42016: Artifactory checks a token’s signature and issuer but fails to enforce its intended scope. An attacker with a low-privileged token can use it for unauthorized actions and privilege escalation.

CVE-2026-82329: An unauthenticated attacker with network access can obtain administrative privileges under the default configuration.

JFrog’s security advisories list the affected branches and fixed versions for each CVE.

Wiz observed attackers chain the first two flaws against self-hosted instances. The sequence began with a request to POST /access/api/v1/aws/token/ , including the trailing slash. Artifactory returned an anonymous-user JWT. The attacker then sent that token to POST /access/api/v1/tokens and received a token with administrator scope.

The escalated token retained the anonymous username while carrying administrator authority. Logs may therefore record later actions under token:anonymous , which can hide the account behind the activity if defenders only for known usernames.

CVE-2026-82329 gives attackers a separate route to an administrator-scoped token. The flaw affects self-hosted deployments across several Artifactory release branches.

Attackers add persistence after access

Administrative access gives an intruder several ways to retain control. Wiz observed attackers create administrator accounts, install malicious Groovy plugins and steal credentials and Access signing keys.

A Groovy plugin can execute code inside the Artifactory service process. Attackers can use that capability to inspect files, run commands, deploy additional payloads and create backdoors. A stolen Access signing key can let an attacker mint valid tokens after defenders patch the original entry point.

Teams should also inspect plugin directories, administrator changes, token activity and configuration access. An upgrade closes the vulnerable route. Incident responders must remove accounts, plugins, keys and other persistence mechanisms that an attacker added before the upgrade.

Patching requires branch-specific checks

JFrog lists these fixed versions for the critical authentication-bypass flaw:

Administrators should select the fixed release for their deployed branch or move to a newer supported release. Teams should review the individual JFrog advisories for CVE-2026-42016 and CVE-2026-42018 because those flaws use separate remediation thresholds.

JFrog says it fortified affected cloud environments. Self-hosted operators still need to patch their systems, restrict Artifactory’s administrative interfaces and review external exposure.

What defenders should investigate

Organizations that exposed Artifactory while a vulnerable version ran should treat the system as compromised until an investigation proves otherwise. Security teams should review:

Requests to /access/api/v1/aws/token/ , /access/api/v1/tokens and /access/api/v1/registry/join .

Activity under the token:anonymous identity.

New administrator accounts and unexpected changes to user metadata.

Groovy files in the Artifactory plugin directories.

Reads of configuration files, Access keys and repository credentials.

New tokens, SSH keys, webshells or outbound connections from the Artifactory host.

Teams should preserve logs and system images before removing artifacts when their incident-response process requires forensic evidence. After containment, rotate repository credentials, signing keys, database secrets and integration tokens. Build systems should also verify artifact digests and rebuild releases that passed through a compromised registry.

Managed services change the risk boundary

Self-hosted Artifactory gives organizations control over network placement, upgrades, storage and integrations. That control also leaves patch scheduling, exposure management and incident response with the customer.

JFrog Artifactory remains a broad package-management option for teams that need one registry across languages and deployment targets. For container-focused workloads, Amazon Elastic Container Registry , Azure Container Registry and Google Artifact Registry offer managed alternatives. Those services shift control-plane maintenance to the provider, while customers still manage identity permissions, network paths, secrets, retention policies and artifact trust.

Pricing comparisons should include storage, data transfer, replication, scanning, support and migration labor. A registry move also requires an inventory of repository layouts, remote mirrors, build credentials, retention rules and release automation. Teams that depend on Artifactory plugins or Groovy-based workflows need replacement designs before migration.

The immediate decision for a self-hosted operator is narrower: identify the release branch, install the fixed version, then investigate the host for access that an attacker may have established before patching.

Please log in or register to join the discussion