Three Artifactory flaws under active exploitation allow auth bypass and admin access
Wiz.io disclosed three Artifactory vulnerabilities that are being actively exploited to bypass authentication and gain administrator access on self-hosted deployments in under five minutes. Patches are available in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 and newer.
- CVE-2026-42018 and CVE-2026-42016 are high severity, CVE-2026-82329 is critical
- Attack chain: unauthenticated POST returns anonymous JWT, then an admin-scoped token
- Post-exploitation includes persistent admin accounts, Groovy plugins and key theft
- Attacks observed within four days of the third bug's disclosure
Read next
Security