How an ‘Anonymous’ Artifactory Token Became an Admin Key for Backdoor Attacks
An Artifactory vulnerability is no longer only a patching concern. Wiz Research says it has observed multiple actors exploit three JFrog flaws in live environments, gain administrator control and, in some cases, leave behind malicious plugins or a Rust backdoor. The registry that delivers trusted software can also become the attacker’s foothold into the build process.
The new evidence changes the urgency of BlackTree’s earlier warning about Artifactory’s default-configuration authentication bypass. That disclosure described what an outsider could do. Wiz has now documented what intruders actually did, and it has identified a second route that chains two other vulnerabilities.
Two routes to administrator control
In the first route, CVE-2026-42018 can expose Artifactory’s internal anonymous-user token to an unauthenticated requester even if anonymous access is disabled. By itself, that token is not an administrator account. CVE-2026-42016 is the missing second step: the server validates a token’s signature and issuer without properly enforcing its scope, allowing that lower-privileged token to acquire administrative authority.
Wiz observed actors use that combination against self-hosted installations between 15 August and 8 September. In some cases, fewer than five minutes passed between the first unauthenticated request and creation of a persistent administrator account. This is confirmed exploitation of a two-flaw chain, not merely public scanning or a proof of concept.
The other route is the previously disclosed CVE-2026-82329, which can provide unauthenticated administrative access under Artifactory’s default configuration. Wiz observed successful exploitation of that flaw from 1 to 8 September. It is a separate path, not a necessary third step in the token chain. Wiz’s examples come from different actors and environments, so they must not be merged into one universal sequence.
The administrator token was only the opening
Across the investigated environments, intruders created new administrator users, deployed malicious Groovy plugins to run commands, uploaded web shells and delivered second-stage binaries. Wiz found a custom Rust backdoor with command-and-control capability in multiple cases involving the two-flaw chain. It does not say every compromised instance contained every one of these components.
That persistence is the real supply-chain risk. Artifactory often holds private packages, build artefacts, integration credentials and routes into CI/CD. A clean version number after an upgrade does not prove that attacker-created accounts, tokens, plugins or altered artefacts have disappeared. A breached registry needs incident response, not only a maintenance window.
Patch the right branch, then investigate what stayed
JFrog lists CVE-2026-42016 in self-hosted versions before 7.133.11. Its current advisory gives branch-specific affected ranges for CVE-2026-42018 and CVE-2026-82329, including several later release trains. Wiz corrected its description of the affected fixed versions for the token-exposure flaw on 11 September. Operators should therefore reconcile the installed build with JFrog’s current advisory and move to the latest supported fixed release for their branch, rather than trusting an older summary or assuming that disabled anonymous access is sufficient.
For installations exposed during the attack window, defenders should review successful requests to the token and registry-join endpoints alongside newly created administrator accounts, privileged tokens, unfamiliar Groovy plugins and unexpected plugin execution. Treat suspicious activity under the internal anonymous identity as a signal worth correlating, not as proof by itself. Review repository changes, build and deployment integrations, and access from the Artifactory host to other systems. If compromise is confirmed, rotate affected credentials from a clean environment and assess whether the server and artefacts need rebuilding or revalidation.
The larger lesson is that the severity label on each bulletin did not describe the combined exposure. One flaw produced a low-privileged token; another accepted its scope; a separate critical flaw offered its own administrator route. Once attackers crossed that boundary, the software repository became a place to persist and potentially influence what downstream systems trust.
Sources
- Wiz Research, Artifactory Under Attack, published 10 September 2026, updated 11 September at 15:00 UTC. The original publication time was not provided.
- JFrog Security Advisories, individual entries first published 27 July, 12 August and 28 August 2026. The page provides dates but no publication times.
- CISA Known Exploited Vulnerabilities catalogue, consulted for exploitation prioritisation.


