Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

https://www.securityweek.com/wp-content/uploads/2024/03/exploit.jpeg

A critical vulnerability in JFrog Artifactory is reportedly being exploited in the wild just days after its public disclosure.

JFrog Artifactory is a widely used solution for managing the full lifecycle of software artifacts, binaries, AI models, containers, and packages.

Artifactory updates released on August 28 patch CVE-2026-82329, a critical authentication bypass vulnerability that can lead to admin access.

“JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” JFrog noted in its advisory.

The company said the patches have already been rolled out to cloud instances, but customers using Artifactory in a self-hosted environment have been advised to update to one of the patched versions, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.

Exposure management firm WatchTowr reported on Tuesday that it has already seen in-the-wild exploitation of CVE-2026-82329, “with attackers minting themselves admin tokens”.

Advertisement....

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more