Executive brief
JFrog Artifactory is a repository manager used to store and distribute software artifacts and dependencies across organizations. A flaw in its default authentication mechanisms allows attackers on the network to gain administrative access without credentials, giving them full control over stored artifacts, builds, and deployment pipelines—potentially enabling malware distribution or supply chain compromise.
Technical details
JFrog Artifactory contains an improper authentication vulnerability in its default configuration that fails to enforce proper access controls. An unauthenticated attacker with network access to the Artifactory instance can exploit this flaw to obtain administrative privileges without providing valid credentials. The vulnerability is reachable over the network and does not require prior authentication or user interaction. Successful exploitation grants an attacker full administrative control of the Artifactory system, allowing them to modify, delete, or exfiltrate artifacts. This vulnerability is known to be actively exploited in the wild. Patches or configuration mitigations should be applied immediately to affected instances.
Affected products
- JFrog Artifactory
Timeline
- 2026-09-02: disclosed
- 2026-09-02: exploited