Skip to finding
§
High
RCE — Artifactory
Confirmed
CVE-2026-82329

Artifactory’s blank default join key lets an anonymous network caller mint a platform-administrator token.

The Access service accepts attacker-authored HS256 join claims and returns a non-expiring administrator token.

Affects

JFrog Artifactory, a self-hosted artifact repository and CI/CD package control plane.

What it enables

Unauthenticated platform-administrator takeover

Reach the self-hosted Artifactory Access API without credentials.→↓Sign chosen join claims with the known default additional join-key value.→↓Submit the forged JWT to /access/api/v1/registry/join.→↓Receive a non-expiring service token carrying administrator scope.→↓Use the token to enumerate users, reset the built-in administrator password, mint further tokens, or modify repositories and artifacts.
Why this matters

We move this above the higher-ranked HPE scope expansion because a shipped default turns anonymous network reachability into administrator access, with runnable code confirming the complete path.

Detail and 2 sources
Required access

Unauthenticated network reachability to a self-hosted Artifactory instance

Affected versions

7.111.4–7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, 7.146.0–7.146.36, 7.161.0–7.161.19

Proof of concept

Public exploit code

An attacker signs chosen join claims with the public blank key, submits them to the registry join endpoint, and receives administrator scope without authenticating.

That token can reset the built-in administrator password, mint more tokens, and modify repositories or artifacts.

The request sequence has been reproduced, and JFrog has published a fixed-version matrix.

Evidence
Pruva verified reproduction with runnable request sequenceJFrog vendor advisory and fixed-version matrix
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026