{
  "id": 11269883,
  "title": "Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin",
  "url": "https://urgent.news/2026/10/01/two-flaws-one-chain-how-jfrog-artifactory-was-pushed-to-admin",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T20:00:21.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/two-flaws-one-chain-how-jfrog-artifactory-was-pushed-to-admin-1b9o"
  },
  "original_language": "en",
  "account": "In August and September 2026, security researchers discovered attackers could exploit two previously patched vulnerabilities in self-hosted JFrog Artifactory to gain administrator control. Both flaws were added to the CISA Known Exploited Vulnerabilities catalog on September 11, with a remediation deadline of September 25. Despite being available for over a month, attackers only exploited the vulnerabilities after September 11. Artifactory is a critical artifact repository used by most build pipelines, including Maven, npm, PyPI, Docker, and Helm. Administrator access allows replacing cached packages and misusing publishing credentials, impacting every build that pulls from the repository. The vulnerabilities are CVE-2026-42016 and CVE-2026-42018. CVE-2026-42016 is an authorization error (CWE-863) affecting versions before 7.133.11, allowing low-privilege tokens to escalate privileges when used. CVE-2026-42018 is an improper authentication issue (CWE-287), enabling anonymous user token generation when disabled. Both flaws have high severity ratings. Attackers typically create an administrator account, install a malicious plugin, and exfiltrate data. To remediate, organizations should upgrade to the appropriate fixed version, restrict access to management and token endpoints, revoke suspect tokens, rotate credentials, and conduct thorough audits.",
  "summary": "Two Flaws, One Chain: How JFrog Artifactory Was Pushed to Admin Between mid-August and early September 2026, security teams observed attackers chaining two patched vulnerabilities in self-hosted JFrog Artifactory to reach administrator control, then install a backdoor. Both flaws entered CISA's Known Exploited Vulnerabilities catalog on September 11, 2026, with a federal remediation deadline of…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}