JFrog Artifactory Vulnerability Chain Enables Admin Control
Score: 9/10

JFrog Artifactory Vulnerability Chain Enables Admin Control

Threat actors are chaining three JFrog Artifactory vulnerabilities to bypass authentication, escalate privileges to administrator, and deploy Rust-based backdoors.

Executive Summary

Between August and September 2026, Wiz Research identified active exploitation of three vulnerabilities in self-hosted JFrog Artifactory instances (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329). While CVE-2026-82329 allows unauthenticated administrative access independently, attackers have also been observed chaining CVE-2026-42018 and CVE-2026-42016 to escalate internal anonymous tokens to full administrative scope. In some instances, attackers moved from initial request to full administrator account creation in under five minutes.

Technically, the attacks involve unauthenticated POST requests to token endpoints to obtain JWTs, followed by the deployment of malicious Groovy plugins for arbitrary code execution. Post-exploitation activities include the installation of custom Rust-based backdoors with command-and-control capabilities, configuration exfiltration, and the theft of cluster join keys. Adversaries frequently created persistent administrator accounts with names like '0xTerror', 'svc_', or legitimate-sounding names like 'jfrog-distribution' to maintain access.

This activity poses a severe risk to software supply chains, as Artifactory serves as a central repository for build pipelines. Compromise allows attackers to manipulate artifacts, steal credentials, and pivot within cloud environments. Organizations are urged to upgrade to remediated versions (e.g., 7.161.20, 7.146.38) and rotate sensitive secrets like cluster join keys and administrator tokens, as patching does not automatically revoke previously minted tokens or remove rogue accounts.

Key Details

Threat Name

CVE-2026-82329

Affects

JFrog Artifactory self-hosted servers below 7.111.20, JFrog Artifactory self-hosted servers below 7.146.8, JFrog Artifactory before 7.133.11, JFrog Artifactory release branches up to 7.161, JFrog Artifactory below 7.161.20, JFrog Artifactory prior to 7.133.11, JFrog Artifactory

Adversary

0xTerror

Malware/Tools

Rust backdoor, Groovy plugins, Rust-based backdoor

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources