JFrog Artifactory: Two Bugs, Two Requests, Admin Access, Now All Three on CISA List
Security / news
JFrog Artifactory: Two Bugs, Two Requests, Admin Access, Now All Three on CISA List
Wiz saw the chain used from August 15; CISA listed the newest bug first and the two older ones nine days later.
An unauthenticated attacker with network access to a self-hosted JFrog Artifactory server could obtain an administrator token in two HTTP requests, using two bugs patched on July 27 and August 12. Wiz Research says multiple attackers did this between August 15 and September 8, and in some cases went from the first request to a new admin account in under five minutes.
CISA has now put all three Artifactory flaws in its Known Exploited Vulnerabilities catalogue: CVE-2026-82329 on September 2, then CVE-2026-42016 and CVE-2026-42018 on September 11. Patches exist for all three.
The chain, and why two medium-looking bugs add up to admin
Wiz's write-up describes CVE-2026-42018 as an improper-authentication flaw: Artifactory may return an internal anonymous-user token to an unauthenticated requester, even with anonymous access disabled. CVE-2026-42016 is a privilege-escalation flaw: the server validates the token's signature and issuer but does not enforce its intended scope.
Chained, the first request (a POST to /access/api/v1/aws/token/) returns the anonymous JWT, and the second (a POST to /access/api/v1/tokens) exchanges it for an admin-scoped token. Both individual bugs carry a High rating. Together they behave like a critical.
CVE-2026-82329 is the most severe of the three: a critical authentication bypass that, per Wiz, affects Artifactory in its default configuration and lets an unauthenticated attacker obtain administrative privileges.
Timeline
| Date (2026) | Event |
|---|---|
| July 27 | Fix for CVE-2026-42016 |
| August 12 | Fix for CVE-2026-42018 |
| August 15 | Wiz's observed exploitation of the chain begins |
| August 28 | Fix for CVE-2026-82329 |
| September 2 | CISA lists CVE-2026-82329 |
| September 8 | End of Wiz's observation window |
| September 11 | CISA lists CVE-2026-42016 and CVE-2026-42018 |
The order is the notable part. Exploitation began three days after the second fix shipped, yet CISA listed the newest bug first and waited until September 11 for the two that had been used for more than three weeks. CISA does not publish its evidence, so the gap is unexplained. The Register reports that attackers moved within days of patches shipping.
What attackers left behind
Wiz found six distinct Groovy backdoors across compromised instances, from disposable command shells to resident implants with anti-forensics features. The most capable, metrics.groovy, injects itself into the Tomcat servlet filter chain and persists only in memory. Wiz also reports that many intruders dropped a custom Rust backdoor for command and control.
That matters for the response. Wiz's own warning is blunt: "If your instance was exposed while vulnerable, assume compromise and hunt for post-exploitation artifacts. Upgrading closes the door but does not evict an attacker who is already inside." Attackers holding stolen Access signing keys can forge valid tokens without returning to the host, so rotating those keys belongs on the list.
Patching has been slow
Wiz's figures, which come from its own cloud visibility and so describe its customer base rather than every Artifactory server, show how many organisations still ran a vulnerable instance.
- CVE-2026-42016 (six weeks after disclosure)59 %
- CVE-2026-42018 (four weeks after disclosure)62 %
- CVE-2026-82329 (two weeks after disclosure)49 %
Source: Wiz Research and The Register, accessed 2026-09-30
Wiz also says 67% of organisations had a vulnerable instance when CVE-2026-42016 was disclosed on July 27. The figures are measured at different ages, so they should not be read as a ranking of which bug is patched fastest.
What to do
Upgrade to a fixed Artifactory release for each of the three CVEs, restrict network access so the Access API is not reachable from the internet, and treat any instance that was exposed during the window as breached until a hunt says otherwise. Start with Groovy plugins you do not recognise and in-memory filters.
For how CISA's catalogue has handled other flaws this month, see our reports on three Linux kernel CVEs and Apple's CoreGraphics zero-day.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.