← Vulnerability feed

Vulnerability record · CVE-2019-17444 · published 12 October 2020

CVE-2019-17444: JFrog Artifactory default admin passwords allow full compromise

Jfrog · Artifactory

JFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials are well known and unchanged, an attacker who can reach the service can log in as an administrator. The flaw affects Artifactory versions prior to 6.17.0.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-521 · Weak password requirements
9.8CVSS 3.1 base score, v2 7.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required and very high EPSS, allowing complete compromise of the repository.

What it is

JFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials are well known and unchanged, an attacker who can reach the service can log in as an administrator. The flaw affects Artifactory versions prior to 6.17.0.

Impact

An unauthenticated network attacker gains full administrative control of the Artifactory instance, including read and write access to all hosted artifacts and configuration. This can lead to supply chain compromise of software distributed through the repository.

Attack surface

The vulnerability is reachable over the network via the Artifactory web interface or API, with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any instance exposed to an untrusted network and left with default credentials is directly at risk.

Exploitation

The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.694 (99.3rd percentile), indicating strong likelihood of exploitation activity. References are vendor advisories and release notes only, with no public exploit tag.

What to do

  • Upgrade Artifactory to version 6.17.0 or later, which is the fixed release per the vendor.
  • Immediately change all default administrative passwords and enforce a strong password policy.
  • Restrict network access to the Artifactory UI and API using firewalls or allowlists so it is not internet-exposed.
  • Audit all accounts for default or weak credentials and disable unused administrative accounts.
  • Enable authentication logging and alerting on administrative logins from unexpected sources.

Detection

  • Search authentication logs for successful logins using known default credentials such as "admin"/"password".
  • Monitor for administrative logins from new or external IP addresses, especially outside normal hours.
  • Alert on creation of new admin users, API keys or tokens, and on bulk artifact downloads or uploads.
  • Review Artifactory configuration and user listings for accounts still using default or weak passwords.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-17444 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2022-0668Jfrog artifactory improper privilege management vulnerabilityJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is…EPSS 0.63%9.8CVE-2018-19971Jfrog artifactory insufficient verification of data authenticity vulnerabilityJFrog Artifactory Pro 6.5.9 has Incorrect Access Control.EPSS 3.0%9.8CVE-2019-9733JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-ForArtifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For…EPSS 53%analysed9.8CVE-2016-10036Jfrog artifactory unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…EPSS 26%

Source: NIST National Vulnerability Database (record CVE-2019-17444), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.