A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access.
The flaw is present in the default configuration of self-managed instances of JFrog Artifactory, a repository manager used to store, organize, secure, and distribute software packages.
An unauthenticated attacker with network access could exploit it to gain administrative permissions.
Researchers at offensive security company watchTowr observed the flaw being exploited by "attackers minting themselves admin tokens."
Details about the flaw are scarce, and JFrog’s advisory does not share many details beyond that the flaw is exploitable in Artifactory’s default configuration.







