JFrog Artifactory Default Authentication Weakness Grants Admin Access
JFrog Artifactory has an authentication flaw that lets unauthenticated network attackers gain admin rights under the software's default configuration.
- Vendor
- JFrog
- Product
- Artifactory
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
JFrog Artifactory contains an authentication weakness that, under default configuration, allows an unauthenticated attacker with network access to obtain administrative privileges. The flaw carries a CVSS base score of 9.8 (critical).
JFrog disclosed the issue on August 28, 2026, in its Artifactory self-managed release notes, alongside a patched build. Organizations running Artifactory on-premises should update immediately and verify their instance is not exposed to networks outside the build pipeline.
Impact
An unauthenticated attacker with network access to an Artifactory instance can gain full administrative control. Artifactory is widely used as a build artifact repository and internal package registry; administrative access provides the ability to read stored secrets, tamper with artifacts, and affect any downstream systems that trust the repository.
Mitigation
Apply the patched Artifactory build referenced in JFrog’s release notes. Additionally, restrict network access to Artifactory to trusted build infrastructure only, regardless of patch status.
