Executive brief
JFrog Artifactory is a widely-used artifact repository platform that manages software binaries and build artifacts for organizations. This vulnerability allows an unauthenticated attacker to obtain an internal anonymous-user token even when anonymous access is disabled, potentially gaining unauthorized access to sensitive artifacts, build information, and dependencies. This could enable supply chain attacks, intellectual property theft, or deployment of malicious artifacts.
Technical details
JFrog Artifactory contains an improper authentication vulnerability in its token issuance mechanism. The vulnerability allows an unauthenticated attacker to request an internal anonymous-user token even when anonymous access is explicitly disabled in the configuration. The flaw stems from insufficient validation of authentication state during token generation. Attackers can exploit this over the network without authentication or user interaction to obtain valid tokens that grant access to the repository. Successful exploitation enables unauthorized access to private artifacts, metadata, and build information. This vulnerability has been observed being actively exploited in the wild. Patches are available from JFrog.
Affected products
- JFrog Artifactory
Timeline
- 2026-09-11: disclosed
- exploited: Reported exploited in the wild