# Wiz reports attackers chained JFrog Artifactory flaws to gain admin control

_Friday, September 11, 2026 at 3:31 AM EDT · Security, Products · Latest · Tier 2 — Notable_

![Wiz reports attackers chained JFrog Artifactory flaws to gain admin control — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgX61WXln9MMGAzqzflpRDt_LZGfB7ZJ_u1fsQhr5FRnml48-E-V-uxtCIF-GERZlt-eBhw3MDT7_6jFgwEDF1ppC7YZlB_CZn-q4_nKD9S3fQTI3kDQFe2Izsq6_NoGnCRtRZckr8Irg9kOJ8Fwghl3qHqwg1zWoN6ff-VsmlCaojw2Divb6L00F34lJk/s1700-nu-rw-lo-l85-e365/jfrog-art.jpg)

Wiz said it observed attacks between August 15 and September 8 in which intruders chained two JFrog Artifactory flaws to take administrator control of self-hosted servers and plant backdoors.

CVE-2026-42018 hands an internal anonymous-user token to an unauthenticated caller; CVE-2026-42016 then lets that low-privilege token be exchanged for one with administrator scope because Artifactory does not check the token's permissions. In some cases attackers reached a new administrator account in under five minutes, and actions appeared in logs as token:anonymous.

JFrog had fixed both flaws before the observed attacks, so only unpatched servers were exposed. Wiz also reported separate exploitation of critical authentication bypass CVE-2026-82329, rated 9.8, on six release branches up to 7.161.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html)

---
Canonical: https://techandbusiness.org/newswire/MCGnjxUFlbzOLyPZWeMXcv
Retrieved: 2026-09-11T10:22:43.421Z
Publisher: Tech & Business (techandbusiness.org)
