hacker-news · Crawled Sep 11, 2026

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Read original article ↗

AI Summary

Attackers exploited a chain of two vulnerabilities in self-hosted JFrog Artifactory instances—CVE-2026-42018 and CVE-2026-42016—to escalate privileges from unauthenticated access to full administrator control. By exploiting the first flaw to obtain an internal anonymous user token and then abusing the second to elevate it to admin scope, attackers created backdoored administrator accounts and deployed malicious Groovy plugins for code execution. In parallel, a separate critical vulnerability, CVE-2026-82329, allowed unauthenticated attackers to gain admin privileges directly, leading to theft of cluster join keys and deployment of custom Rust-based backdoors on compromised servers.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.