Executive Summary
Between August and September 2026, Wiz Research identified active exploitation of three vulnerabilities in self-hosted JFrog Artifactory instances (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329). While CVE-2026-82329 allows unauthenticated administrative access independently, attackers have also been observed chaining CVE-2026-42018 and CVE-2026-42016 to escalate internal anonymous tokens to full administrative scope. In some instances, attackers moved from initial request to full administrator account creation in under five minutes.
Technically, the attacks involve unauthenticated POST requests to token endpoints to obtain JWTs, followed by the deployment of malicious Groovy plugins for arbitrary code execution. Post-exploitation activities include the installation of custom Rust-based backdoors with command-and-control capabilities, configuration exfiltration, and the theft of cluster join keys. Adversaries frequently created persistent administrator accounts with names like '0xTerror', 'svc_', or legitimate-sounding names like 'jfrog-distribution' to maintain access.
This activity poses a severe risk to software supply chains, as Artifactory serves as a central repository for build pipelines. Compromise allows attackers to manipulate artifacts, steal credentials, and pivot within cloud environments. Organizations are urged to upgrade to remediated versions (e.g., 7.161.20, 7.146.38) and rotate sensitive secrets like cluster join keys and administrator tokens, as patching does not automatically revoke previously minted tokens or remove rogue accounts.
Key Details
Threat Name
CVE-2026-82329
Affects
JFrog Artifactory self-hosted servers below 7.111.20, JFrog Artifactory self-hosted servers below 7.146.8, JFrog Artifactory before 7.133.11, JFrog Artifactory release branches up to 7.161, JFrog Artifactory below 7.161.20, JFrog Artifactory prior to 7.133.11, JFrog Artifactory
Adversary
0xTerror
Malware/Tools
Rust backdoor, Groovy plugins, Rust-based backdoor
