πŸ”΄ CVE-2026-82329

CVE-2026-82329 is a critical authentication bypass vulnerability (CWE-287) in JFrog Artifactory that allows unauthenticated remote attackers to obtain administrative privileges under default configuration. With a CVSS score of 9.8, no privileges or user interaction required, and confirmed active exploitation by CISA KEV listing, this represents an immediately weaponisable internet-facing threat. Successful exploitation gives the attacker full administrative control over the Artifactory server, its artifact repositories, and any integrated build/CI-CD pipeline credentials.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-28

Added to CISA KEV: 2026-09-02 5 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-14)

Summary

CVE-2026-82329 is a critical authentication bypass vulnerability (CVSS score 9.8) affecting JFrog Artifactory that allows an unauthenticated attacker to gain full administrative privileges. By exploiting a flaw in the core authentication mechanism on self-hosted instances running default configurations, an attacker can mint legitimate administrative access tokens through a single HTTP request, posing a severe risk to software supply chain integrity and overall platform security [1][2].

Exploitation

  • Active Exploitation: The vulnerability is being actively exploited in the wild, with reports confirming exploitation attempts occurring shortly after public disclosure.
  • Threat Actors: While widespread automated exploitation has been observed, specific threat actor groups or ransomware campaigns have not been definitively linked to the activity as of early September 2026.
  • Proof-of-Concept/Exploitation: The exploit is considered trivial, requiring only a single HTTP request to mint administrative tokens, which has facilitated rapid exploitation [1].
  • Prerequisites: Exploitation is remote and does not require authentication or user interaction; it only requires network access to a vulnerable, self-hosted Artifactory instance running with default configurations [2][3].

Affected Products & Patches

  • Affected Versions: Self-managed (self-hosted) JFrog Artifactory deployments are primarily affected; users should consult JFrog's official security advisory for the comprehensive list of impacted versions.
  • Patch Availability: JFrog released a patch for this vulnerability on August 28, 2026.
  • Mitigations: Organizations unable to patch immediately are advised to disable anonymous access within the Artifactory configuration and reconfigure authentication settings to ensure all endpoints require verified credentials.

Impact

  • Access & Capability: Successful exploitation grants the attacker full platform administrative privileges, enabling them to create backdoor users, access sensitive repositories, modify binaries or artifacts, and enumerate internal system information [2][4].
  • Business Risk: For internet-facing deployments, this vulnerability represents a critical risk of complete system compromise, potential software supply chain poisoning (by tampering with stored artifacts), and severe data exfiltration, making immediate remediation essential for any exposed infrastructure [1].

Sources

  1. CVE-2026-82329: JFrog Artifactory Authentication Bypass Exploitation ...

    CVE-2026-82329 is a critical (CVSS 9.8) unauthenticated authentication bypass in self-hosted JFrog Artifactory that lets an anonymous attacker mint a full platform admin access token with a single HTTP request.

  2. CVE-2026-82329: CVE-2026-82329: Critical Authentication Bypass and ...

    CVE-2026-82329 is a critical authentication bypass vulnerability in the core authentication mechanisms of JFrog Artifactory. Classified under CWE-287, this security weakness allows remote, unauthenticated attackers to bypass authentication controls and obtain full administrative privileges on vulner…

  3. NVD-CVE-2026-82329

    CVE-2026-82329 Detail Description JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

  4. CVE-2026-82329: Critical JFrog Artifactory Flaw

    JFrog patched CVE-2026-82329, a critical Artifactory flaw that lets unauthenticated attackers gain admin access and create backdoor users.