Skip to finding
important · RCE — Artifactory

Two Artifactory token flaws compose into unauthenticated administrative control and server-side code execution.

Affects

JFrog Artifactory, a self-hosted artifact repository used in software build and deployment pipelines.

An unauthenticated endpoint discloses an internal anonymous-user JWT, and missing scope validation lets that token mint administrator authority.

Detail and 2 sources

The chain was used to create administrators, execute operating-system commands through a Groovy plugin, and install a persistent Rust backdoor.

JFrog has fixed the token flaws, but the remediation does not establish complete revocation of access or persistence created before upgrade.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026