Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Administration Launches Blitz to Find Elusive Voter Fraud Ahead of Midterms

    September 2, 2026

    Judge Lacked Power to Vacate Bowe Bergdahl’s Conviction, Court Finds

    September 2, 2026

    A vital tenet of US equity markets is under threat

    September 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Administration Launches Blitz to Find Elusive Voter Fraud Ahead of Midterms
    • Judge Lacked Power to Vacate Bowe Bergdahl’s Conviction, Court Finds
    • A vital tenet of US equity markets is under threat
    • X shifts US creator payouts from Stripe to X Money
    • Meet Switchyard: A Rust Proxy and Library That Routes and Translates LLM Traffic Across OpenAI and Anthropic APIs
    • Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
    • Ondo Says US Rules Can Support Stock Perpetual Futures
    • Invaders storm Indigenous Amazon land, threatening isolated people
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 2, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access.

    The flaw is present in the default configuration of self-managed instances of JFrog Artifactory, a repository manager used to store, organize, secure, and distribute software packages.

    An unauthenticated attacker with network access could exploit it to gain administrative permissions.

    Researchers at offensive security company watchTowr observed the flaw being exploited by “attackers minting themselves admin tokens.”

    Tweet

    Details about the flaw are scarce, and JFrog’s advisory does not share many details beyond that the flaw is exploitable in Artifactory’s default configuration.

    Vercel CEO Guillermo Rauch warned that the flaw’s impact could extend beyond compromising Artifactory itself.

    “Administrative access to Artifactory reaches released artifacts that downstream systems already trust and pull automatically,” Collin Hogue-Spears, Senior Director of Solution Management at application security company Black Duck, told BleepingComputer.

    Spears also notes that JFrog treats access tokens as independent credentials with their own expiration and revocation mechanisms, so upgrading the Artifactory binary does not by itself invalidate an already-issued token.

    Because organizations use Artifactory to store binaries and packages consumed by build and deployment systems, attackers with administrative access could replace trusted artifacts and potentially execute malicious code on downstream systems.

    Rauch also speculated that the vulnerability might be connected to recent research involving autonomous AI agents.

    JFrog addressed the issue on August 28 in Artifactory versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20. The vendor says that JFrog Cloud environments were already protected.

    An attacker forging their own admin tokens means they can perform various sensitive actions, such as enumerating users, groups, and federated topologies, reading artifacts, changing security configurations, and poisoning existing packages.

    However, the extent of the compromise, and whether servers were actually breached, is unclear. Victim counts, telemetry details, and indicators of compromise (IoCs) are also unclear.

    BleepingComputer has contacted JFrog to confirm the reported activity, but we have not received a response yet.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Admin Artifactory critical exploit Flaw Forge hackers JFrog tokens
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Reform UK bans three journalists from its conference after critical reporting | Reform UK

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Ransomware protection for MSPs: A 6-point checklist for faster recovery

    Microsoft Defender flags legitimate Google search links as malicious

    Dropbox accounts breached through Lenovo email verification flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Administration Launches Blitz to Find Elusive Voter Fraud Ahead of Midterms

    September 2, 2026

    Judge Lacked Power to Vacate Bowe Bergdahl’s Conviction, Court Finds

    September 2, 2026

    A vital tenet of US equity markets is under threat

    September 2, 2026

    X shifts US creator payouts from Stripe to X Money

    September 2, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Administration Launches Blitz to Find Elusive Voter Fraud Ahead of Midterms

    September 2, 2026

    Judge Lacked Power to Vacate Bowe Bergdahl’s Conviction, Court Finds

    September 2, 2026

    A vital tenet of US equity markets is under threat

    September 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.