CVE-2026-82329 is a critical authentication bypass vulnerability (CWE-287) in JFrog Artifactory that allows unauthenticated remote attackers to obtain administrative privileges under default configuration. With a CVSS score of 9.8, no privileges or user interaction required, and confirmed active exploitation by CISA KEV listing, this represents an immediately weaponisable internet-facing threat. Successful exploitation gives the attacker full administrative control over the Artifactory server, its artifact repositories, and any integrated build/CI-CD pipeline credentials.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-28
Added to CISA KEV: 2026-09-02 5 DAYS BETWEEN CVE AND KEV
CVE-2026-82329 is a critical authentication bypass vulnerability (CVSS score 9.8) affecting JFrog Artifactory that allows an unauthenticated attacker to gain full administrative privileges. By exploiting a flaw in the core authentication mechanism on self-hosted instances running default configurations, an attacker can mint legitimate administrative access tokens through a single HTTP request, posing a severe risk to software supply chain integrity and overall platform security [1][2].
CVE-2026-82329 is a critical (CVSS 9.8) unauthenticated authentication bypass in self-hosted JFrog Artifactory that lets an anonymous attacker mint a full platform admin access token with a single HTTP request.
CVE-2026-82329 is a critical authentication bypass vulnerability in the core authentication mechanisms of JFrog Artifactory. Classified under CWE-287, this security weakness allows remote, unauthenticated attackers to bypass authentication controls and obtain full administrative privileges on vulnerβ¦
CVE-2026-82329 Detail Description JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
JFrog patched CVE-2026-82329, a critical Artifactory flaw that lets unauthenticated attackers gain admin access and create backdoor users.