Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted Artifactory deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits can then enable dangerous post-authentication activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures.
Security company Wiz.io, which disclosed the three vulnerabilities, reports that attackers are chaining the flaws to achieve privilege escalation and full administrator control of self-hosted Artifactory instances:
These CVEs are trivial to exploit, a handful of unauthenticated HTTP requests. If your instance was exposed while vulnerable, assume compromise and hunt for post-exploitation artifacts. Upgrading closes the door but does not evict an attacker who is already inside [...].
The three vulnerabilities are CVE-2026-42018, rated high severity, which "may cause Artifactory to return an internal anonymous-user token to an unauthenticated requester, even when anonymous access is disabled"; CVE-2026-42016, also rated high severity, which causes Artifactory to fail to properly validate a request's token so "an attacker with low-privileged access may be able to use a valid token to perform unauthorized actions and gain elevated privileges"; and CVE-2026-82329, rated critical severity, which allows an unauthenticated attacker to obtain administrative control.
As noted by Wiz.io, two of the vulnerabilities can be chained in an attack leading to persistent admin accounts and further post-exploitation.
Every exploitation followed a similar shape. An unauthenticated
POST /access/api/v1/aws/token/with a trailing slash returned HTTP 200 with a JWT for the internal anonymous user, exploiting CVE-2026-42018. The actor then exchanged that JWT for an admin-scoped token throughPOST /access/api/v1/tokens, which returned HTTP 200 and exploited the CVE-2026-42016 scope-validation flaw. The escalated token kept the anonymous username but carried admin authority, so later requests appear with an actor oftoken:anonymous.
Separately, CVE-2026-82329 can be exploited to obtain an admin-scoped token directly. Once administrative access is obtained, attackers have been observed creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, harvesting credentials and Access signing keys, establishing backdoors, and deploying anti-forensics mechanisms.
Wiz also notes that, in some observed cases, attackers completed the exploitation and established administrative access in under five minutes.
Commenting on the disclosure on LinkedIn, cybersecurity specialist Erik York argued that:
Artifactory sits at the center of a LOT of software supply chains. This is exactly the kind of bug that turns into next year's SolarWinds story if it's not patched fast.
Jim Nitterauer, senior director of information security at Graylog, stressed the importance of patching all affected systems to keep supply chains safe:
Because Artifactory sits at the heart of software build pipelines, a compromise is a direct supply-chain risk and patch adoption has lagged badly, with attacks observed within four days of disclosure of the third bug.
All Artifactory self-hosted environments should be immediately patched to any version fixing the vulnerabilities, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20, or newer depending on the deployed release branch.