What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification.
I believe the technical term for that is "big oof"
That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.