

ETHICAL USE ONLY – AUTHORIZED SECURITY TESTING
This repository provides tools for authorized security professionals, blue teams, and penetration testers only.
Unauthorized access to computer systems is illegal under CFAA (US), Computer Misuse Act (UK), TCK 243/244 (Turkey), and similar laws worldwide.
📖 Vulnerability Overview
CVE‑2026‑82329 is a critical authentication bypass vulnerability in self-hosted JFrog Artifactory (versions 7.111.x through 7.161.x) that allows an unauthenticated attacker to obtain a full platform administrator token by abusing the JFrog Access cluster join mechanism.
How it works
- Blank join key trust – JFrog Access trusts a phantom join key whose value is an empty string. Its signing secret is therefore the deterministic value
32 * 0x20 (spaces).
- Forged join JWT – an attacker forges an HS256 JWT signed with this known secret and
kid = SHA256("").
- SERVICE token issued –
POST /access/api/v1/registry/join returns a SERVICE token with scp=admin without any authentication.
- Admin token exchange –
POST /access/api/v1/tokens with scope=applied-permissions/admin&audience=* yields a full platform admin token.
- Impact – full repository takeover, token theft, admin user creation, artifact poisoning, supply-chain attacks, and lateral movement into connected services (Xray, Mission Control, Distribution). Upgrade immediately!
Affected Versions
- 7.111.4 – 7.111.20 – vulnerable
- 7.117.0 – 7.117.27 – vulnerable
- 7.125.0 – 7.125.19 – vulnerable
- 7.133.0 – 7.133.28 – vulnerable
- 7.146.0 – 7.146.36 – vulnerable
- 7.161.0 – 7.161.19 – vulnerable
Patch
- Upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 or newer.
- If upgrade is not possible, restrict network access to Artifactory (never expose it to the internet) and rotate all admin tokens as a temporary workaround.
| Tool | Purpose | Intended User |
|---|
exploit.py | Full weaponized toolkit with JWT forging, admin token exchange, admin user creation, mass scanning, stealth mode, proxy rotation, interactive menu, and full attack chain. | Red teams / authorized pentesters |
safechecker.py | Non‑intrusive vulnerability checker that detects Artifactory version, validates exposure, and assesses risk without obtaining any token or executing any payload. Generates JSON reports. | Blue teams / security auditors |
📊 Feature Comparison
| Feature | exploit.py | safechecker.py |
|---|
| Vulnerability detection | ✅ | ✅ |
| Version detection | ✅ | ✅ |
| Forged join JWT | ✅ | ❌ |
| Service token mint | ✅ | ❌ |
| Admin token exchange | ✅ | ❌ |
| Admin user creation | ✅ | ❌ |
| List repositories | ✅ | ❌ |
| List users | ✅ | ❌ |
| Dump configuration | ✅ | ❌ |
| Dump tokens | ✅ | ❌ |
| Full attack chain | ✅ | ❌ |
| Interactive menu | ✅ | ❌ |
| Mass scanning (multi‑thread) | ✅ | ✅ |
| Proxy support | ✅ | ✅ |
| Proxy rotation | ✅ | ❌ |
| Tor support (anonymity) | ✅ | ❌ |
| User‑Agent rotation (OPSEC) | ✅ | ❌ |
| Jitter (OPSEC) | ✅ | ❌ |
| Adaptive rate limiter | ✅ | ❌ |
| Non‑intrusive (safe) mode | ❌ | ✅ |
| Version report | ✅ | ✅ |
| Anonymous access check | ❌ | ✅ |
| JSON report | ✅ | ✅ |
| Log cleanup (anti‑forensic) | ✅ | ❌ |
| Custom User‑Agent | ✅ | ✅ |
| SSL verification control | ✅ | ✅ |
🎯 Use Case Summary
| Scenario | Recommended Tool |
|---|
| Blue Team – verifying if your Artifactory is vulnerable | safechecker.py |
| Security Audit – non‑intrusive vulnerability assessment | safechecker.py |
| Red Team – authorized penetration testing with full exploitation | exploit.py |
| Bug Bounty – responsible disclosure testing | safechecker.py |
| Mass Scanning – checking multiple targets for vulnerability | exploit.py (detect‑only) |
| Incident Response – checking if systems are compromised | safechecker.py |
⚙️ Installation
git clone https://github.com/tc4dy/CVE-2026-82329-PoC-Exploit
cd CVE-2026-82329-PoC-Exploit
pip install -r requirements.txt
requirements.txt
requests
urllib3
curl_cffi
📋 Parameters
exploit.py Parameters
| Parameter | Description |
|---|
-u, --url | Single target Artifactory URL (e.g. http://artifactory.example.com:8082) |
-f, --file | File containing list of targets (one per line) for mass scanning |
--create-admin | Create persistent admin user (format: USER:PASS) |
--keep-admin | Keep created admin user (do not cleanup after scan) |
--token-only | Only print admin token (single target) |
--interactive | Interactive menu after exploitation |
--service-id | Service ID for join JWT (default: jfrt@01) |
-t, --threads | Number of threads for multi‑target (default: 10) |
--timeout | Request timeout (default: 25s) |
--retry | Max retries (default: 3) |
--proxy | HTTP/HTTPS proxy (e.g. http://127.0.0.1:8080) |
--proxy-list | File with proxies for rotation (one per line) |
--jitter | Random jitter (0‑2 sec) between requests |
--stealth | Enable stealth mode (UA rotation + X‑Forwarded‑For) |
--curl-cffi | Use curl_cffi for TLS fingerprint impersonation |
--full | Full attack: all modules |
--dump-config | Dump system configuration |
--dump-tokens | Dump all access tokens |
--list-repos | List repositories |
--list-users | List users |
--detect | Detection only (no admin token exchange) |
--exploit | Perform full exploitation |
-o, --output | Save JSON report to file |
-v, --verbose | Verbose output |
-q, --quiet | Quiet mode |
safechecker.py Parameters
| Parameter | Description |
|---|
-u, --url | Single target Artifactory URL (e.g. http://artifactory.example.com:8082) |
-f, --file | File containing list of targets (one per line) |
-t, --threads | Number of threads for multi‑target (default: 5) |
--timeout | Request timeout (default: 10s) |
-v, --verbose | Verbose output |
-o, --output | Save JSON report to file |
💥 Scenarios