Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin
Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin Between mid-August and early September 2026, security teams observed attackers chaining two patched vulnerabilities in self-hosted JFrog Artifactory to reach administrator control, then install a backdoor. Both flaws entered CISA's Known Exploited Vulnerabilities catalog on September 11, 2026, with a federal remediation deadline of…
In August and September 2026, security researchers discovered attackers could exploit two previously patched vulnerabilities in self-hosted JFrog Artifactory to gain administrator control. Both flaws were added to the CISA Known Exploited Vulnerabilities catalog on September 11, with a remediation deadline of September 25. Despite being available for over a month, attackers only exploited the vulnerabilities after September 11.
Artifactory is a critical artifact repository used by most build pipelines, including Maven, npm, PyPI, Docker, and Helm. Administrator access allows replacing cached packages and misusing publishing credentials, impacting every build that pulls from the repository. The vulnerabilities are CVE-2026-42016 and CVE-2026-42018. CVE-2026-42016 is an authorization error (CWE-863) affecting versions before 7.133.11, allowing low-privilege tokens to escalate privileges when used.
CVE-2026-42018 is an improper authentication issue (CWE-287), enabling anonymous user token generation when disabled. Both flaws have high severity ratings. Attackers typically create an administrator account, install a malicious plugin, and exfiltrate data. To remediate, organizations should upgrade to the appropriate fixed version, restrict access to management and token endpoints, revoke suspect tokens, rotate credentials, and conduct thorough audits.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.