The Exploit Bulletin

Archives
Log in
Subscribe
September 11, 2026

The Exploit Bulletin — Friday, September 11, 2026: 1 issue requires action

Friday, September 11, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: JFrog Artifactory Self-Hosted


1. Token-scope validation flaw in JFrog Artifactory chained with auth bypass for admin takeover (CVE-2026-42016)

PRIVILEGE ESCALATION · CRITICAL · CVSS 8.1

Wiz published on 2026-09-10 that this chain is being used against Artifactory servers and VulnCheck added the CVE to its KEV catalog the same day; an unpatched self-hosted instance exposed to the network is at risk of full administrative compromise of the artifact supply chain.

Self-hosted Artifactory validates only an access token's signature and issuer, not its scope, allowing a low-privileged token holder to escalate privileges. Wiz Research reports attackers chaining this with CVE-2026-42018 and the authentication bypass CVE-2026-82329 to gain administrative access to Artifactory instances.

Affected: JFrog Artifactory Self-Hosted < 7.111.20; JFrog Artifactory Self-Hosted >= 7.117.0 < 7.117.27; JFrog Artifactory Self-Hosted >= 7.125.0 < 7.125.19; JFrog Artifactory Self-Hosted >= 7.133.0 < 7.133.28 (original fix 7.133.11); JFrog Artifactory Self-Hosted >= 7.146.0 < 7.146.8

How to Test: Check the running Artifactory version (Administration > System Info or the release shown in the UI footer) against the affected ranges above; any self-hosted build below 7.111.20, 7.117.27, 7.125.19, 7.133.28 or 7.146.8 is vulnerable. Because the observed attacks chain in CVE-2026-82329 (auth bypass), also confirm you are on a build listed as fixed for that CVE (7.161.19, 7.146.36, 7.133.28, 7.125.19, 7.117.27, 7.111.21). Review Artifactory access and request logs for token-based requests performing admin-level actions from unfamiliar sources, audit for newly created admin users or access tokens, and check recently modified or uploaded artifacts in critical repositories.

How to Patch: Upgrade self-hosted Artifactory to a release that closes the whole chain: 7.161.19, 7.146.36, 7.133.28, 7.125.19, 7.117.27 or 7.111.21 (or later on the corresponding line). If the upgrade must wait, restrict network access to the Artifactory instance to trusted sources and rotate existing access tokens after patching.

Evidence: VulnCheck KEV · Wiz Research: in-the-wild exploitation of CVE-2026-42016/42018/82329 chain

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Saturday, September 12, 2026: 1 issue requires action Older → The Exploit Bulletin — Thursday, September 10, 2026: 5 issues require action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.