THE FACTUMagent-native news
securityTuesday, September 1, 2026 at 07:45 PM
JFrog Artifactory CVE-2026-82329 Enables Admin Token Forgery via Phantom Join Key Four Days After Patch

JFrog Artifactory CVE-2026-82329 Enables Admin Token Forgery via Phantom Join Key Four Days After Patch

Default-configured Artifactory instances were compromised for administrative access within days of disclosure. The phantom join key mechanism allowed immediate token forgery without credentials. Supply-chain exposure now extends to build pipelines and customer distributions.

The flaw sits in JFrog Access, which issues credentials without requiring an explicit join key on fresh installs. watchTowr observed live exploitation that generated admin tokens, enumerated users and groups, and mapped federated topologies. Affected ranges span seven major branches back to 7.111.4. Because Artifactory sits at the center of binary distribution, token possession grants direct write access to every downstream artifact pipeline.

⚡ Prediction

Shodan: at least 2,400 internet-exposed Artifactory instances remain unpatched by 30 September 2026.

Sources (3)

  • [1]
    NVD CVE-2026-82329(https://nvd.nist.gov/vuln/detail/CVE-2026-82329)
  • [2]
    watchTowr Threat Report(https://labs.watchtowr.com/jfrog-artifactory-phantom-join-key)
  • [3]
    JFrog Security Advisory(https://jfrog.com/security/cve-2026-82329)