Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens
Hackers exploit JFrog Artifactory flaw to create admin tokens, gaining administrative access. JFrog addresses the issue with new versions.
Intelligence analysis by Qwen 2.5 (3B)

JFrog Artifactory, a repository manager, has a critical flaw exploited by hackers to forge admin tokens, enabling administrative access. JFrog has released new versions to address the issue.
Hackers found a way to trick JFrog's software into giving them special permission to do anything they want. JFrog fixed the problem by making new versions of their software.
Analysis
{"heading_1":"The Vulnerability","content_1":"JFrog Artifactory, a popular repository manager, has a critical authentication bypass vulnerability (CVE-2026-82329) that can be exploited by attackers to create admin tokens. This flaw is present in the default configuration of self-managed instances of JFrog Artifactory.","heading_2":"Impact and Exploitation","content_2":"The vulnerability allows an unauthenticated attacker with network access to gain administrative permissions. Researchers at offensive security company watchTowr observed attackers minting their own admin tokens, indicating the flaw is being actively exploited.","heading_3":"Vendor Response","content_3":"JFrog addressed the issue with new versions of Artifactory, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20. The vendor notes that JFrog Cloud environments were already protected, but the extent of the compromise remains unclear."}
Key points
- JFrog Artifactory has a critical vulnerability that can be exploited to gain administrative access.
- The vulnerability is present in the default configuration of self-managed instances.
- JFrog has released new versions to address the issue.
The fix from JFrog should prevent attackers from using this vulnerability to cause harm. Organizations should update their software to protect against this risk.
If attackers have already compromised systems, the damage could be significant. Organizations should monitor for any unusual activity and update their software promptly.


