JFrog Artifactory Authentication Bypass Vulnerability: Critical Threat
- Severity
- HIGH
- Affected component
- jfrog artifactory (npm)
- Patched version
- Not yet available
A critical authentication bypass vulnerability in the JFrog Artifactory npm package has been exploited in the wild. Users of JFrog Artifactory are advised to upgrade to the latest version and review access controls.
What happened
The JFrog Artifactory npm package contains a critical authentication bypass vulnerability tracked as CVE-2026-82329. This flaw allows unauthenticated attackers with network access to obtain administrative privileges under default configurations. Threat actors have begun exploiting this vulnerability to mint admin tokens, as reported by multiple independent sources. The vulnerability was patched by JFrog with Artifactory version 7.161.20 released on August 28, 2026.
The affected versions include 7.161.0 > 7.161.19, 7.146.0 > 7.146.36, 7.133.0 > 7.133.28, 7.125.0 > 7.125.19, 7.117.0 > 7.117.27, and 7.111.4 > 7.111.21. The issue resides in JFrog Access, which is designed to issue and validate credentials. Instances without an additional join key configured receive a 'phantom' join key that attackers can abuse to forge access and mint administrator-level credentials.
What to do about it
- Upgrade to the latest version of JFrog Artifactory to mitigate the vulnerability.
- Review and strengthen access controls to prevent unauthorized administrative access.
- Monitor your systems for any signs of unauthorized activity or admin token minting.
- Consult the primary sources for the most up-to-date information and patches.
How 0Day would have caught this
jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using JFrog Artifactory versions 7.161.0 > 7.161.19, 7.146.0 > 7.146.36, 7.133.0 > 7.133.28, 7.125.0 > 7.125.19, 7.117.0 > 7.117.27, or 7.111.4 > 7.111.21, you are affected.
What should I do right now?
Upgrade to the latest version of JFrog Artifactory and review your access controls.
Has this been exploited in the wild?
Yes, this vulnerability has been exploited in the wild by attackers to mint admin tokens.
Sources
- NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
- Attackers Pounce on Critical Artifactory Flaw Following Disclosure
- Stop Malicious Packages with the Spectra Assure Community Plugin for JFrog Artifactory
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild