← Back to blog

Attackers Quickly Exploit JFrog Artifactory Admin Token Flaw

A critical authentication bypass in JFrog Artifactory is being actively exploited just days after its patch release. Organizations using default configurations are at high risk of unauthorized admin access.

TL;DR

  • CVE-2026-82329 is a critical auth bypass flaw in JFrog Artifactory (CVSS 9.8).
  • Attackers are already exploiting it to mint admin tokens post-disclosure.
  • Default configurations leave systems vulnerable to takeover.
  • Organizations should patch immediately and audit for suspicious activity.
  • watchTowr first reported active exploitation in the wild.

Threat actors have wasted no time exploiting a newly disclosed critical vulnerability in JFrog Artifactory. The flaw, tracked as CVE-2026-82329, allows attackers to bypass authentication and gain administrative privileges under default configurations.

Security researchers from watchTowr confirmed that malicious actors are actively targeting unpatched instances to mint admin-level tokens. This rapid exploitation highlights the importance of swift patch deployment and continuous monitoring for organizations relying on Artifactory for artifact management.

Vulnerability Overview

  • CVE-2026-82329 has a CVSS score of 9.8, indicating critical severity.
  • It affects JFrog Artifactory when running with default settings.
  • The flaw enables authentication bypass leading to admin token creation.
  • Patched versions were released shortly before active exploitation began.

Impact and Recommendations

  • Successful exploitation grants full administrative control over Artifactory instances.
  • Organizations should update to the latest patched version immediately.
  • Review logs for unusual token generation or privilege escalation attempts.
  • Enforce least-privilege access controls and monitor API activity closely.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.