Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Read original article ↗AI Summary
Attackers exploited a chain of two vulnerabilities in self-hosted JFrog Artifactory instances—CVE-2026-42018 and CVE-2026-42016—to escalate privileges from unauthenticated access to full administrator control. By exploiting the first flaw to obtain an internal anonymous user token and then abusing the second to elevate it to admin scope, attackers created backdoored administrator accounts and deployed malicious Groovy plugins for code execution. In parallel, a separate critical vulnerability, CVE-2026-82329, allowed unauthenticated attackers to gain admin privileges directly, leading to theft of cluster join keys and deployment of custom Rust-based backdoors on compromised servers.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.