Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers exploited two previously patched vulnerabilities in self-hosted JFrog Artifactory to gain administrator access and install malicious software. The first flaw, CVE-2026-42018, allows unauthenticated requests to be converted into administrator tokens, even when anonymous access is disabled. The second flaw, CVE-2026-42016, enables low-privilege tokens to be upgraded to administrator scope.

Once attackers obtained these administrator tokens, they installed Groovy plugins and a Rust backdoor to establish command-and-control channels and gain further control over compromised servers. The impact of this attack includes compromised administrator accounts, code execution, and command-and-control capabilities, as well as the potential to join Artifactory clusters.

To fix the vulnerabilities, users must upgrade to the appropriate patched version for their release branch and rotate the cluster join key while revoking any tokens issued since August 28.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Tech

More from Friday 11 September →