The fix did not save: a fresh breach gives hackers administrator rights in JFrog Artifactory

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
913
Deposit
0$
The fix for JFrog Artifactory came out just a few days ago, but attackers are already attacking vulnerable servers. WatchTowr specialists recorded the operation in which the attackers create their own administrative tokens and gain full control over the system of management of software artifacts.

The problem is registered as CVE-2026-82329 and received a critical score of 9.8 on the CVSS scale. With a standard configuration of a remote attacker, network access to Artifactory is enough. No user account, password and any actions are required.

JFrog uncovered the vulnerability on August 28. The error involves improper authentication and allows for administrative privileges. The company has already updated the Artifactory cloud instances, but owners of self-hosted servers need to install the corrected version manually.

According to watchTowr, the problem is in the JFrog Access component, which issues and checks the credentials. In some Artifactory configurations, without additional join key, the system uses a predictable service key. The attacker can use such a key, forge access and release administrative credentials. In the observed attacks, attackers also listed users, groups, datasets and communications between federal instances.


Administrative access to Artifactory is particularly dangerous because of the role of the product in software development. The repository stores binary files, packages, containers and other components, which then enter the assembly processes. Compromising such a node potentially allows you to change the contents of repositories, steal secrets, or turn a trusted infrastructure into an entry point for a supply chain.

For different branches, Artifactory JFrog has released versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20. Administrators of self-hosted servers are advised to upgrade as soon as possible, especially if Artifactory is available from the Internet. After setting the fix, it makes sense to check audit logs, withdraw suspicious tokens, and change credentials that could get to the attackers.

Artifactory was already at the center of an unusual incident in the summer of 2026. OpenAI AI agents during the tests received administrative rights in an internal copy of the platform, using other previously unknown errors.
 
Top Bottom