Attackers Chain JFrog Flaws to Gain Admin Control and Plant Backdoors

A sophisticated attack chain exploited two JFrog Artifactory vulnerabilities to seize admin control and plant persistent backdoors in software supply chains.

By Central
Highlights
  • Attackers chained two flaws in JFrog Artifactory to escalate from an anonymous token to full admin control.
  • The attack exploited unpatched servers, with some compromises occurring in under five minutes.
  • A third critical vulnerability, CVE-2026-82329, was also exploited independently during the same period.

Attackers have chained two distinct security flaws in JFrog Artifactory, the software repository that countless build pipelines depend on, to seize administrator control of self-hosted instances and plant persistent backdoors. The campaign, observed by cloud security firm Wiz between August 15 and September 8, underscores how a single unpatched component in the software supply chain can cascade into a full compromise. JFrog had already issued fixes for both vulnerabilities before the attacks began, meaning only servers that had not been updated remained vulnerable. Yet the speed of exploitation — in some cases under five minutes from initial request to administrator account creation — and the subsequent actions taken by attackers reveal a threat landscape where the window for patching is shrinking dramatically.

The Two-Flaw Attack Chain: From Anonymous Token to Admin

Neither vulnerability alone grants administrative control. The attack relies on chaining them in a specific sequence. The first, tracked as CVE-2026-42018, causes Artifactory to return an internal anonymous-user token to a caller who has not even logged in — even when anonymous access has been explicitly disabled. This token is meant for internal use only, but the flaw leaks it to any unauthenticated network request.

With that low-privilege token in hand, the attacker then exploits the second flaw, CVE-2026-42016. This vulnerability allows that anonymous token to be exchanged for a token with administrator scope. The root cause: Artifactory validates a token’s cryptographic signature and checks who issued it, but does not verify what the token is actually permitted to do. So a token intended for the internal anonymous user — which should have minimal rights — can be swapped at Artifactory’s token-creation endpoint for one that carries full administrative privileges.

In every case Wiz examined, the pattern was consistent. The attacker sent an unauthenticated request to a token endpoint and received the internal anonymous token, then immediately presented it at the token-creation endpoint to obtain an administrator-scoped token. Critically, that second token retains the anonymous username. Any administrative actions taken with it appear in audit logs under token:anonymous rather than under a named account, making detection harder for teams that rely solely on log monitoring.

The chain is only effective when both vulnerabilities exist on the same server. Closing either one breaks the attack. In JFrog’s published version ranges, CVE-2026-42016 affects versions before 7.133.11, while CVE-2026-42018 affects a broader set of branches below specific patch levels. The 7.146 and 7.161 branches fall outside the range for CVE-2026-42016, meaning servers on those newer releases are not susceptible to this particular chain — but as we will see, they remain exposed to a separate critical flaw.

A Third, More Dangerous Vulnerability: CVE-2026-82329

While Wiz tracked the two-flaw chain, a third Artifactory vulnerability was exploited independently between September 1 and September 8. CVE-2026-82329 is a critical authentication bypass rated 9.8 on the CVSS scale. It requires no other flaw. An unauthenticated attacker with network access to the Artifactory server can obtain administrator privileges through it alone. The vulnerability targets Artifactory’s default configuration and affects six release branches up to version 7.161.

By September 1, attackers had already begun creating administrator tokens for themselves through this flaw, just days after JFrog disclosed it. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalog of known exploited vulnerabilities on September 2, giving federal agencies a September 5 deadline to patch. Fastly, a content delivery network, reported that a public exploit appeared on September 1 and was followed by immediate scanning. Fastly counted approximately 406,000 exploitation attempts across its platform on September 2 alone — the busiest day. Those are attempts observed in traffic, not confirmed compromises, but the scale is staggering.

On servers taken through CVE-2026-82329, Wiz observed attackers reading system configuration files and, in several cases, extracting the cluster join key — the shared secret that Artifactory nodes use to register with one another. Possession of the join key allows an attacker to authenticate any new node to the cluster, potentially maintaining access even after the initial vulnerability is patched.

What Attackers Did with Administrator Access

The actions taken after gaining admin control varied across compromised servers, and Wiz noted that no single actor carried out every step observed. However, a clear pattern of post-exploitation activity emerged.

Attackers consistently created new administrator accounts and left them in place. Many carried proof-of-concept names such as 0xTerror, or names following patterns like svc_ and labadmin_ appended with random characters. Some attackers tried to blend in, using names that appeared legitimate, such as jfrog-distribution, jfrog-insight, and repo-service. Wiz’s report includes a list of attacker IP addresses and payload hashes for defenders to check against their logs.

Beyond account creation, attackers installed malicious Groovy plugins through Artifactory’s plugin framework. This allowed them to execute arbitrary code on the server. Some ran shell commands via the plugin execution endpoint to explore the file system and list directories. A dropper was used to pull a binary over HTTP, write it to a world-writable directory such as /tmp, and open a command-and-control channel. In multiple cases, Wiz observed a custom Rust backdoor with its own command-and-control capabilities being deployed.

The presence of these backdoors means that even if the administrator accounts are removed after patching, the attackers may retain access through the malware. For the critical CVE-2026-82329, Fastly explicitly advises treating any exposed server as fully compromised. “A patch does not revoke tokens already minted,” the company said. That statement applies equally to tokens obtained through the two-flaw chain.

Patch Guidance and Its Limitations

For self-hosted Artifactory instances, the only reliable fix is to upgrade to the fixed build for your specific release branch. JFrog provides version details in its security advisories. Cloud-hosted instances require no action, as JFrog applies patches centrally.

The following summarizes the affected and fixed versions for each CVE:

  • CVE-2026-42018 (anonymous token leak): Affects versions below 7.111.20, and below 7.117.27, 7.125.19, 7.133.28, and 7.146.8 on those branches. Fixed in 7.111.20, 7.117.27, 7.125.19, 7.133.28, 7.146.8.
  • CVE-2026-42016 (token privilege escalation): Affects versions before 7.133.11. Fixed in 7.133.11. Note that JFrog lists only one fixed version for this CVE and does not indicate whether later builds on older branches (such as 7.117.28) also close it. This gap may leave some installations uncertain about their true patch status.
  • CVE-2026-82329 (authentication bypass): Affects versions below 7.111.21, and below 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 on those branches. Fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20.

JFrog does publish a workaround for CVE-2026-82329 for organizations that cannot upgrade immediately: generate a random value and add it as an extra join key in system.yaml. This ensures that only your own keys are accepted when a service tries to register, blocking the authentication bypass. No similar interim workaround is available for the two chained flaws.

Patching is essential, but it does not undo the damage. Administrator accounts created by the attacker remain in the system. Tokens that were minted before the patch continue to be valid. And if the cluster join key was exfiltrated, the attacker can still use it to authenticate new nodes. For these reasons, Fastly recommends rotating the platform join key, revoking all access tokens issued since August 28, and conducting a thorough review of administrator accounts, repositories, and configuration changes.

How to Detect Compromise

The clearest indicator of exploitation is an account performing actions that its privileges should not allow. The internal anonymous user — or any low-privilege account — creating tokens, listing users, or reading and writing plugins is a strong red flag. Because tokens obtained through the chain retain the token:anonymous username, logs showing administrative actions attributed to that identity are a direct sign of compromise.

Defenders should also look for administrator accounts that were not created through normal administrative processes. In addition to the names mentioned above, any account with a name that mimics system services but appears out of place warrants investigation. Wiz’s full report includes a list of known attacker addresses and payload hashes that can be used for threat hunting.

For CVE-2026-82329, the exploitation does not always leave user-account traces because the attacker may create tokens without creating a named user. Checking for API calls to token endpoints from unusual IP addresses during the period from September 1 onward is a useful starting point. Fastly’s analysis noted that scanning for vulnerable servers began on September 1 and peaked on September 2, so any unusual token creation after those dates should be treated with high suspicion.

The Broader Implications for Software Supply Chain Security

Artifactory occupies a critical position in the software supply chain. It is the repository from which CI/CD pipelines pull dependencies, and in many organizations it also stores internally built artifacts. A compromise of Artifactory can lead to tampered packages being distributed to downstream consumers, creating a supply chain attack that could affect thousands of organizations. The fact that attackers in this campaign not only established administrator access but also installed backdoors and extracted join keys indicates a clear intent to maintain long-term persistence.

These events also highlight a recurring pattern: vulnerabilities in developer tools and infrastructure platforms are being exploited within days or even hours of disclosure. The two-flaw chain exploited servers that had not updated to patches released weeks earlier. The critical CVE-2026-82329 saw active exploitation within days of its public disclosure and the release of a proof-of-concept exploit. The window for patching is closing rapidly, and organizations that cannot apply security updates immediately must have compensating controls — such as network segmentation, strict access controls, and anomaly detection — in place.

Furthermore, the involvement of OpenAI researchers in the discovery of several Artifactory flaws, including CVE-2026-42016, adds an unexpected dimension. JFrog confirmed in July that OpenAI models had exploited an Artifactory zero-day during an internal evaluation, though neither company specified which CVE records matched the flaws used. This raises questions about the intersection of AI systems and vulnerability discovery — and about whether AI-driven attacks could accelerate exploitation even further in the future.

For now, the priority for any organization running self-hosted JFrog Artifactory is to determine which versions are in use, apply the appropriate patches, and then conduct a thorough investigation for signs of compromise. The attackers were methodical: they created accounts, deployed backdoors, and extracted credentials. Patching without cleanup leaves the door open for reinfection. The combination of the two-flaw chain and the independent critical flaw means that servers on both older and newer branches are at risk, making a comprehensive audit essential.

As supply chain attacks grow more sophisticated, the Artifactory incidents serve as a stark reminder that a repository is not just a storage system — it is a gateway to everything that depends on it. Securing that gateway requires not only timely patching but also continuous monitoring, rapid incident response, and a willingness to treat any exposure as a potential full compromise. The attackers in this campaign demonstrated that they understand the value of the platform better than some of its administrators do. The responsibility falls on every organization using these tools to close the gap.

Share This Article