chiprook
← Security
SecuritySeptember 20, 2026, 08:40

Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory

JFrog disclosed CVE-2026-82329 (CVSS 9.8) in self-hosted Artifactory: an empty default join key lets an unauthenticated attacker sign a join JWT and obtain an admin token. Exploitation in the wild was recorded on September 1, 2026; CISA added related vulnerabilities to its KEV catalog.

Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory
#JFrog#Artifactory#CISA
Read next
Security

CrowdSec confirms source code stolen in supply chain attack

Security

FBI: scammers impersonate police and demand payment under arrest threats

Security

Spain reports first end-to-end data breach carried out by an AI agent

Security

Iranian hackers suspected in attack on Hyundai Glovis tanker off Texas