Artifactory Vulnerabilities Under Active Exploitation Enable Authentication Bypass and Admin Access
Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures. By Sergio…
Three critical vulnerabilities in the Artifactory software platform have been actively exploited, enabling attackers to bypass authentication and gain administrator access, according to security firm Wiz.io. The flaws, which include CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, can be chained together to escalate privileges and establish persistent control over affected self-hosted Artifactory deployments within just five minutes.
The first two vulnerabilities, rated high severity, allow attackers to obtain an internal anonymous-user token and use valid tokens for unauthorized actions, potentially escalating privileges. The third flaw, marked as critical severity, directly grants attackers administrative control. Once administrative access is achieved, attackers have been seen creating persistent administrator accounts, deploying malicious plugins for code execution, stealing credentials and signing keys, setting up backdoors, and implementing anti-forensics measures.
Wiz.io's disclosure notes that these vulnerabilities are trivial to exploit with a few unauthenticated HTTP requests. The security company advises that once an instance is compromised, it should be assumed that an attack has occurred. Upgrading to the latest patched versions is recommended to mitigate the risk, but it does not automatically remove an attacker already inside the system.
Artifactory, which acts as a central repository in many software supply chains, is particularly vulnerable as a compromise can directly impact supply chain security. Experts urge immediate patching of all affected systems to prevent potential supply chain disruptions and attacks.
Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.