JFrog Artifactory: Unauth Token Chain to Admin + Rust Backdoor

By George Bailey   Published: 09/16/26   Updated: 09/16/26   3 min read

Your build pipeline’s artifact brain is under active attack. Attackers have been chaining JFrog Artifactory flaws to go from no login to administrator in minutes — then planting Groovy plugins and a custom Rust backdoor.

If self-hosted Artifactory was reachable and unpatched through early September, patching alone does not revoke the tokens or admin accounts they already minted.

What happened

Wiz Research reported in-the-wild exploitation between August 15 and September 8, 2026. Two flaws were chained:

In observed cases, attackers moved from the first request to a new admin account in under five minutes. Logs often show powerful actions as token:anonymous. A third critical auth bypass, CVE-2026-82329 (CVSS 9.8), was exploited separately against newer branches and can grant admin alone.

CISA added CVE-2026-42016 and CVE-2026-42018 to KEV on September 11, 2026 (federal due September 25). CVE-2026-82329 was already on KEV with an earlier due date.

Why it matters

Artifactory sits in the path of every binary your pipelines trust. Admin on that box means malicious packages, poisoned plugins, stolen join keys, and a foothold that survives the next developer push.

Supply-chain impact is the blast radius — not just one server’s uptime.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.