Tech News
← Home  ·  All topics

Admin Tokens

1 GoKawiil brief on this topic

JFrog Artifactory bug lets attackers forge admin tokens in active exploits

A critical authentication bypass, CVE-2026-82329, in self-managed JFrog Artifactory deployments is being actively exploited to mint fraudulent administrator tokens without any prior authentication. The flaw sits in Artifactory's default configuration, and watchTowr researchers say attackers are already using it in the wild. JFrog patched the issue on August 28 across several version branches, and confirmed its cloud-hosted environments were never at risk.