Affected Systems
JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations with no additional join key configured. Self-managed instances exposed to network access are at risk.
Exploitation Status
Active exploitation confirmed as of September 1, 2026, by watchTowr. Attackers are generating admin tokens and enumerating users, groups, and credential sets. Exploitation began within days of public disclosure on August 28, 2026.
Business Impact
CVSS 9.8 critical authentication bypass enabling unauthenticated attackers to obtain administrative privileges. Attackers can forge access tokens via JFrog Access component by abusing phantom join keys in default configurations. Administrative access enables supply chain attacks including build pipeline tampering, binary poisoning, lateral movement to production systems, and downstream malicious code distribution to customers. No user interaction or authentication required.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade self-managed JFrog Artifactory to version 7.161.20 or later patched versions released August 28, 2026
- Inspect JFrog Artifactory audit logs for unauthorized admin token generation, user enumeration, and suspicious access patterns since August 28, 2026
- Rotate all JFrog Artifactory credentials, API keys, and access tokens, prioritizing administrative and service accounts
- Review connected CI/CD pipelines, build systems, and downstream repositories for unauthorized changes, backdoors, or malicious artifacts
- Configure additional join keys on JFrog Access to eliminate phantom join key vulnerability in default configurations
