Artifactory token-refresh via legacy credential endpoint security flaw
Vulnerability
Updated: 27.08.2026 21:36
· First: 27.08.2026 21:36
· 📰 2 src / 2 articles
· H score: 44
Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeover risk for affected deployments. The flaw enabled privileged access through a weak refresh path rather than normal authentication. JFrog was alerted after the abuse was uncovered.