ALERT: Active exploitation of three vulnerabilities in self-hosted JFrog Artifactory. Attackers take two independent paths to administrator control, then persist with lookalike accounts, stolen cluster join keys, Groovy plugins, web shells, and a custom Rust backdoor. Artifactory sits in the software supply chain: admin compromise can poison artifacts that developers and CI/CD already trust.
Why this matters
JFrog Cloud was remediated by JFrog for CVE-2026-82329 (no customer action). Self-hosted operators must patch and hunt historical logs. About 67% of Artifactory orgs had at least one instance vulnerable to CVE-2026-82329 at disclosure; roughly 49% remained two weeks later.
With SAI Secure, you are protected automatically against new and emerging threats like this. Give your existing security platforms the CTI and hunt logic they need to protect critical assets, with no surprise or usage-based costs.
The three CVEs
CVE-2026-42018: anonymous-user token exposure (High, CWE-287)
Published 12 Aug 2026. Artifactory can return an internal anonymous-user JWT to an unauthenticated caller even when anonymous access is disabled.
A POST request to /access/api/v1/aws/token/ (with a trailing slash) returned HTTP 200. The highest-confidence probe pattern is a 401 on the bare path, then 200 on a variant from the same client. This identity is not an administrator by itself.
Patched floors include 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8 (or later).
CVE-2026-42016: token scope not validated (High, CWE-863)
Published 27 Jul 2026. Self-hosted versions before 7.133.11 check token signature and issuer but not scope.
A low-privilege JWT (such as the one from CVE-2026-42018) can be exchanged at POST /access/api/v1/tokens for an admin-scoped token. Later admin calls may still log as token:anonymous, which hides the privilege level actually in use.
Patched: 7.133.11 and later.
CVE-2026-82329: unauthenticated admin (Critical 9.8, CWE-287, CISA KEV)
Published 28 Aug 2026. Under default configuration, an unauthenticated attacker with network access can obtain administrative privileges.
A POST request to /access/api/v1/registry/join returned HTTP 200/201 with an admin-scoped token. The root cause is that the application treats an empty additional-join-key configuration as a trusted empty key. Mass scanning was observed by Fastly using the User-Agent JFrogArtifactory/7.146.25 starting 1 Sep 2026.
Patched floors include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.
If patching is not possible immediately, set a unique shared.security.additionalJoinKeys (or environment variable JF_SHARED_SECURITY_ADDITIONALJOINKEYS) and restart Access. Use a unique hex key and do not reuse examples from advisories.
Attack path #1: chain
- Use CVE-2026-42018 to steal an internal anonymous JWT.
- Use CVE-2026-42016 to exchange that JWT for admin scope.
- Create a persistent administrator via
PUT /api/security/users/or/access/api/ui/users/(HTTP 201).
Observed 15 Aug through 8 Sep 2026. Compromise from an unauthenticated request to a new admin account was seen in under five minutes.
Attack path #2: direct
Use CVE-2026-82329 alone: the unauthenticated join API leads directly to an admin token. Observed 1 through 8 Sep 2026. Several groups reused the same initial request before diverging in post-exploitation.
What defenders should do now
Patch self-hosted Artifactory to a fixed floor for all three CVEs. If you cannot patch immediately, apply the join-key workaround for CVE-2026-82329 and treat Access restarts as part of the change window.
Hunt historical Access and Artifactory logs for the probe and exploitation patterns above: trailing-slash token endpoints, unexpected 401-then-200 pairs from the same client, token exchanges that elevate scope, registry join responses that mint admin tokens, and rapid creation of lookalike administrator accounts. Review for stolen cluster join keys, unexpected Groovy plugins, web shells, and unknown Rust binaries on Artifactory hosts.
Assume supply-chain trust may already be at risk if an instance was admin-compromised. Validate artifact integrity, signing, and downstream CI/CD consumers that pulled from affected repositories during the exposure window.
Operationalizing in SAI Secure
Seed SAI Secure with the CVE entities, probe URLs, User-Agent strings, and post-exploitation behaviors from this campaign. Enrich matching hosts and accounts, classify confirmed true positives, and push hunt-ready logic into the SIEM and EDR platforms your SOC already runs. Pair short-lived IOC sweeps with durable detections for join-key abuse, anonymous-to-admin token elevation, and suspicious admin-user creation so coverage survives the next packaging change.
Conclusion
Self-hosted Artifactory is high-value supply-chain infrastructure. Two independent paths to admin, active scanning, and fast post-exploitation leave little room for delayed patching. Fix versions now, hunt the historical window, and keep behavioral coverage in place after the next tool rename.