{
  "id": 10514396,
  "title": "Artifactory Vulnerabilities Under Active Exploitation Enable Authentication Bypass and Admin Access",
  "url": "https://urgent.news/2026/09/28/artifactory-vulnerabilities-under-active-exploitation-enable",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T19:00:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/09/artifactory-vulnerabilities/"
  },
  "original_language": "en",
  "account": "Three critical vulnerabilities in the Artifactory software platform have been actively exploited, enabling attackers to bypass authentication and gain administrator access, according to security firm Wiz.io. The flaws, which include CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, can be chained together to escalate privileges and establish persistent control over affected self-hosted Artifactory deployments within just five minutes.\n\nThe first two vulnerabilities, rated high severity, allow attackers to obtain an internal anonymous-user token and use valid tokens for unauthorized actions, potentially escalating privileges. The third flaw, marked as critical severity, directly grants attackers administrative control. Once administrative access is achieved, attackers have been seen creating persistent administrator accounts, deploying malicious plugins for code execution, stealing credentials and signing keys, setting up backdoors, and implementing anti-forensics measures.\n\nWiz.io's disclosure notes that these vulnerabilities are trivial to exploit with a few unauthenticated HTTP requests. The security company advises that once an instance is compromised, it should be assumed that an attack has occurred. Upgrading to the latest patched versions is recommended to mitigate the risk, but it does not automatically remove an attacker already inside the system.\n\nArtifactory, which acts as a central repository in many software supply chains, is particularly vulnerable as a compromise can directly impact supply chain security. Experts urge immediate patching of all affected systems to prevent potential supply chain disruptions and attacks.",
  "summary": "Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures. By Sergio…",
  "key_points": [
    "Three critical vulnerabilities in Artifactory exploited for authentication bypass and admin access",
    "First two vulnerabilities allow obtaining internal anonymous-user token for unauthorized actions",
    "Third flaw directly grants attackers administrative control with persistent access"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}