Новости компьютерной безопасности:

  Latest News

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

С сайта: Vulnerability(cybersecuritynews.com)

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

Author: Abinaya

A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges.

WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin tokens.” An attacker with a valid administrator token could control the affected Artifactory environment, including repositories, user accounts, access permissions, build artifacts, and software packages stored in the platform.

JFrog disclosed the vulnerability on August 28, 2026, and classified it as critical. The company described CVE-2026-82329 as an improper authentication issue, tracked under CWE-287.

Under the default configuration, a remote attacker does not need valid credentials to exploit the weakness and may obtain administrative privileges.

JFrog Artifactory Auth Bypass Exploited
Artifactory is widely used by development and DevOps teams to manage packages, container images, binaries, build dependencies, and other software artifacts.

Because it often sits within CI/CD pipelines, compromising an Artifactory server can pose a serious risk to the software supply chain.

Attackers who gain admin control may be able to alter repository settings, create privileged accounts, steal stored secrets, access private packages, or attempt to introduce malicious artifacts into trusted build and deployment workflows.

According to exposure management firm WatchTowr, the reported creation of administrator tokens is particularly concerning because they can provide persistent access even after an organization changes passwords or terminates active user sessions.

Security teams should investigate whether any unexpected administrator tokens, new privileged users, unusual API activity, or configuration changes were created around the time the vulnerable instance was exposed.

JFrog said its cloud environments have already been fortified, meaning customers using the vendor-managed cloud service do not need to take action for this specific issue.

However, organizations running self-hosted Artifactory must upgrade immediately to a fixed release on their supported branch. The patched versions are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.

The affected ranges include Artifactory versions 7.111.4 through 7.111.21, 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36, and 7.161.0 through 7.161.19.

Organizations should also restrict external access to Artifactory management interfaces, review reverse-proxy and firewall rules, and ensure only trusted networks can reach administrative endpoints.

Teams should inspect access logs for unfamiliar source IP addresses, failed or abnormal authentication requests, token-generation events, and calls to user, permission, or repository administration APIs.

Administrators should treat any internet-exposed, unpatched self-hosted Artifactory deployment as potentially compromised.

After patching, organizations should revoke and reissue administrator tokens, review all privileged accounts, validate repository integrity, and examine CI/CD credentials that may have been accessible through the platform.

The active exploitation report makes rapid remediation essential. A compromised artifact repository can turn a single authentication bypass into a broader breach affecting developers, build systems, production workloads, and downstream software users.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.