Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Ravie LakshmananSep 01, 2026Vulnerability / Supply Chain Attack

Recently, threat actors have been exploiting a critical security vulnerability in JFrog Artifactory that was patched just days ago, as reported by watchTowr.

The vulnerability, identified as CVE-2026-82329 and with a CVSS score of 9.8, allows for an authentication bypass that could potentially result in gaining administrative access in Artifactory.

According to JFrog’s release notes, the security flaw was addressed in Artifactory version 7.161.20, which was released on August 28, 2026. This vulnerability impacts various versions of the software, including 7.161.0 to 7.161.19, 7.146.0 to 7.146.36, and others.

CEO of Vercel, Guillermo Rauch, highlighted the seriousness of the issue, stating that it can lead to Remote Code Execution (RCE) due to Artifactory hosting binaries. He emphasized the potential for malicious activities beyond just poisoning the system.

Further investigation revealed that the vulnerability resides in JFrog Access, enabling attackers to forge access and create administrator-level credentials. As of September 1, 2026, threat actors have started exploiting this flaw to generate admin tokens and gather sensitive information.

It is crucial for organizations using self-managed versions of JFrog Artifactory to promptly apply patches to exposed systems, review audit logs, rotate credentials, and check for any unauthorized access or changes.