jfrog-artifactory-oss is vulnerable to Authentication Bypass
98
Critical Risk
JFrog Artifactory has an authentication weakness that, under the default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. A successful exploit yields full administrative control of the Artifactory instance, and therefore of the artifacts, container images, and packages it serves to downstream builds. This issue is reported to be exploited in the wild within days of disclosure, with attackers minting themselves administrative tokens. JFrog has released patched builds on the supported 7.111, 7.117, 7.125, 7.133, 7.146, and 7.161 branches; after upgrading, review administrator accounts and issued access tokens, revoke anything unrecognized, and treat artifacts published while exposed as suspect.
You are affected if you are using a version that falls within the vulnerable range and you run a self-hosted JFrog Artifactory instance. All self-hosted instances prior to the versions patched on 28 August 2026 are affected, and under the default configuration the issue is reachable without any credentials. Cloud-hosted Artifactory instances have already been patched by JFrog and are not vulnerable.
jfrog-artifactory-oss is vulnerable to Authentication Bypass in versions 7.111.4 - 7.111.20, 7.117.0 - 7.117.27, 7.125.0 - 7.125.19, 7.133.0 - 7.133.28, 7.146.0 - 7.146.36 and 7.161.0 - 7.161.19.
Upgrade the jfrog-artifactory-pro and/or the jfrog-artifactory-oss library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.