← Vulnerability feed

Vulnerability record · CVE-2019-9733 · published 11 April 2019

CVE-2019-9733: JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-For

Jfrog · Artifactory

Artifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For header. An unauthenticated attacker can spoof that header, log in with the default access-admin credentials, and use the API to mint authentication tokens for any user, including admin.

9.8 CVSS 3.0 Critical EPSS 53% · top 1.1%
9.8CVSS 3.0 base score, v2 7.5
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass with public exploit code and a CVSS of 9.8 that yields full control of the artifact repository.

What it is

Artifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For header. An unauthenticated attacker can spoof that header, log in with the default access-admin credentials, and use the API to mint authentication tokens for any user, including admin.

Impact

The attacker gains full control of all artifacts and repositories managed by Artifactory, including the ability to impersonate the admin account.

Attack surface

Reachable over the network via HTTP requests to the Artifactory console; no authentication or user interaction is required, only the ability to send a crafted X-Forwarded-For header.

Exploitation

Not listed in CISA KEV, but public exploit references exist (Packet Storm, CipherTechs) and EPSS is 0.52948 (98.9th percentile), indicating high likelihood of exploitation.

What to do

  • Upgrade Artifactory to 6.8.6 or later, which addresses this issue per the vendor release notes.
  • Change the default access-admin credentials and disable or restrict the access-admin account if not needed.
  • Do not trust client-supplied X-Forwarded-For headers; configure the reverse proxy to strip or overwrite them and only accept connections from known proxies.
  • Restrict network access to the Artifactory console and API to trusted management networks.
  • Rotate all Artifactory user and admin tokens after patching in case of prior compromise.

Detection

  • Search Artifactory access logs for requests to the access-admin or password-reset endpoints containing an X-Forwarded-For header.
  • Alert on successful logins to the access-admin account, especially from non-localhost source addresses.
  • Monitor for API calls that generate authentication tokens for multiple or privileged users in a short window.
  • Review audit logs for unexpected token creation or repository permission changes tied to access-admin.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9733 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2022-0668Jfrog artifactory improper privilege management vulnerabilityJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is…EPSS 0.63%9.8CVE-2019-17444JFrog Artifactory default admin passwords allow full compromiseJFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials …EPSS 69%analysed9.8CVE-2018-19971Jfrog artifactory insufficient verification of data authenticity vulnerabilityJFrog Artifactory Pro 6.5.9 has Incorrect Access Control.EPSS 3.0%9.8CVE-2016-10036Jfrog artifactory unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…EPSS 26%

Source: NIST National Vulnerability Database (record CVE-2019-9733), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.