JFrog Artifactory Authentication Bypass

critical Web App Scanning Plugin ID 115462

Synopsis

JFrog Artifactory Authentication Bypass

Description

Self-hosted JFrog Artifactory versions 7.111.4 prior to 7.111.21, 7.117.x prior to 7.117.28, 7.125.x prior to 7.125.20, 7.133.x prior to 7.133.29, 7.146.x prior to 7.146.38 and 7.161.x prior to 7.161.20 suffer from an authentication bypass vulnerability. The JFrog Access service trusts a blank join key on a default installation, and the HMAC secret derived from that blank key is a known value. A remote and unauthenticated attacker can therefore forge a cluster join token, submit it to the unauthenticated cluster join endpoint and be granted an access token scoped to `admin`, which can be exchanged for a platform administrator token to read the server configuration, enumerate all the platform tokens or tamper with the hosted artifacts.

Solution

Upgrade to JFrog Artifactory version 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 or later.

See Also

https://docs.jfrog.com/releases/docs/jfrog-security-advisories

Plugin Details

Severity: Critical

ID: 115462

Type: Check Based

Published: 9/8/2026

Updated: 9/8/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-82329

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-82329

Vulnerability Information

CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/28/2026

Vulnerability Publication Date: 8/27/2026

CISA Known Exploited Vulnerability Due Dates: 9/5/2026

Reference Information

CVE: CVE-2026-82329