Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Summary

A critical authentication bypass vulnerability, identified as CVE-2026-82329, has been discovered in JFrog Artifactory. Attackers are actively exploiting this flaw to generate administrative tokens, granting them unauthorized access to the platform.

IFF Assessment

FOE

The exploitation of a critical vulnerability allowing unauthorized administrative access poses a significant threat to organizations using JFrog Artifactory.

Severity

9.8 Critical

Defender Context

This vulnerability in JFrog Artifactory allows attackers to bypass authentication and gain administrative privileges, enabling them to compromise sensitive code repositories and development pipelines. Defenders should prioritize patching JFrog Artifactory instances and monitor for signs of unauthorized token creation or administrative access.

Read Full Story →