CVE-2026-82329

Published Aug 28, 2026

Last updated 10 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-82329 describes an authentication weakness found in JFrog Artifactory. Under its default configuration, this vulnerability allows an unauthenticated attacker with network access to gain administrative privileges. This flaw is present in various versions of JFrog Artifactory, including those before 7.111.21, and specific ranges within 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36/37, and 7.161.0 through 7.161.19.

Description
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Source
reefs@jfrog.com
NVD status
Analyzed
Products
artifactory

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
JFrog Artifactory Improper Authentication Vulnerability
Exploit added on
Sep 2, 2026
Exploit action due
Sep 5, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

reefs@jfrog.com
CWE-287

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

8

  1. 🚨 JFROG ARTIFACTORY UNDER ACTIVE ATTACK — AUTH BYPASS LEADS TO ADMIN CONTROL AND BACKDOORS Wiz Research has confirmed active in-the-wild exploitation of THREE vulnerabilities affecting self-hosted JFrog Artifactory environments: * CVE-2026-82329 — Critical authentication

    @DailyDarkWeb

    13 Sept 2026

    4552 Impressions

    1 Retweet

    18 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  2. Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.

    @Sunil_kumawat17

    11 Sept 2026

    71 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42

    @rst_cloud

    11 Sept 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB

    @yactina1336

    10 Sept 2026

    62 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 JFrog Artifactory Authentication Bypass (CVE-2026-82329) Exploited in the Wild Critical Vulnerability Alert! JFrog Artifactory is affected by CVE-2026-82329. 🔍 Identify Targets via ZoomEye: Search Dork: app="JFrog Artifactory" Exposure: 17.9k instances identified globa

    @zoomeyebot

    10 Sept 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA KEV: CVE-2026-82329 JFrog Artifactory improper auth. Default config can give unauthenticated admin access. Active exploitation confirmed in Sep 2 catalog update. #cybersecurity #infosec #CISA #KEV #Artifactory https://t.co/k0Sha2yMEB

    @Caldura7

    7 Sept 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA KEV listing for JFrog Artifactory (CVE-2026-82329) confirms active exploitation. A 9.8 CVSS is notable, but the key is the default config allowing unauth admin access. Check your Artifactory instances for non-default auth settings immediately.

    @BytesNora

    5 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🐦 🚨 Chrome patched an actively exploited V8 0-day (CVE-2026-85046) — update now. JFrog Artifactory auth bypass (CVE-2026-82329, CVSS 9.8) is being exploited to forge admin tokens. SonicWall SMA1000 bugs (CVSS 10.0) just hit CISA's KEV list. #infosec #CVE #0day

    @ita_ipo

    4 Sept 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CYBER — Une faille critique de JFrog Artifactory est désormais activement exploitée. La vulnérabilité CVE-2026-82329, notée CVSS 9,8/10, permet à un attaquant non authentifié ayant accès au service de contourner l’authentification et d’obtenir des privilèges

    @ActuX_off

    4 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. The Fastly Threat Research team is tracking a sharp escalation in exploitation attempts for CVE-2026-82329, a critical authentication bypass in self-hosted JFrog Artifactory. Since its disclosure on August 28, we’ve observed activity surge from low-level probing to opportunisti

    @fastly

    4 Sept 2026

    906 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  11. A CVSS 9.8 just turned build servers into admin keys. CVE-2026-82329: an unauthenticated attacker forges admin tokens in JFrog Artifactory. Already exploited in the wild. On CISA's KEV list as of Sept 2. The scary part isn't the CVE. It's the blast radius 🧵 https://t.co/04sz

    @fiks_cloud

    3 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 🐦 🚨 SonicWall SMA1000 zero-days (CVE-2026-83548, CVSS 10.0 + CVE-2026-83549) chained for unauth RCE, actively exploited, added to CISA KEV. JFrog Artifactory CVE-2026-82329 (CVSS 9.8) also exploited itw — forges admin tokens. Patch now. #infosec #CVE #0day

    @ita_ipo

    3 Sept 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CISA adds seven actively exploited flaws to the KEV catalog, including two in SonicWall SMA1000, one in JFrog Artifactory and one in Kestra OSS. CVE-2026-83548 enables unauthenticated SSRF while CVE-2026-83549 allows OS command execution. CVE-2026-82329 grants remote admin

    @WorldCyberNewsX

    3 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Exploitation windows continue to shrink. The recent JFrog Artifactory authentication bypass (CVE-2026-82329) saw in-the-wild use just days after disclosure. Continuous vulnerability monitoring and prioritized patching of supply-chain tools are now essential.

    @Lumideezy

    3 Sept 2026

    95 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 1/5 A critical Artifactory flaw was patched on August 28. Days later, watchTowr observed attackers exploiting it to mint admin tokens. CVE-2026-82329 is an unauthenticated auth bypass affecting self-hosted deployments under default configuration. 🧵 https://t.co/mOaQrJw4v8

    @SOCMinute

    2 Sept 2026

    15 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  16. تجاوز المصادقة دون تسجيل دخول في JFrog Artifactory يستحق فهماً عملياً، لا قراءة سطحية فقط. يتناول المحتوى CVE-2026-82329 من زاوية قابلة لإعادة الاختبار عبر Docker lab، مع PoC

    @fad_777

    2 Sept 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ✅ CALLED IT — CVE-2026-82329 just landed in the CISA #KEV catalog. ThreatClaw's AI agents flagged this 5 days before CISA listed it. That's 1 confirmed KEV calls — and counting. See what's predicted next 👇 https://t.co/HYMvDH8ply #CyberSecurity #ThreatIntelligence #CV

    @XManinderSingh

    2 Sept 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. ✅ CALLED IT — CVE-2026-82329 just landed in the CISA #KEV catalog. ThreatClaw's AI agents flagged this 5 days before CISA listed it. That's 32 confirmed KEV calls — and counting. See what's predicted next 👇 https://t.co/HYMvDH8ply #CyberSecurity #ThreatIntelligence #C

    @XManinderSingh

    2 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 JFrog Artifactory Açığı Aktif İstismarda CVE-2026-82329 (CVSS 9.8), kimlik doğrulaması olmadan saldırganların yönetici yetkisi kazanmasına izin veriyor. Açık yayınlandıktan sadece birkaç gün sonra istismar edilmeye başlandı. #CVE #CyberSecurity  http

    @KubbeSiber

    2 Sept 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Most CISOs I work with underestimate how fast attackers exploit disclosed vulnerabilities. JFrog Artifactory’s critical CVE-2026-82329 was weaponized within days of public patch release. #CyberSecurity #InfoSec #VAPT

    @ThreatRix_Ai

    2 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass. https://t.co/jebAYcLQ8L #ThreatIntel #CVE_2026_82329 #watchTowr https://t.co/5YGBBBq3KK

    @threadlinqs

    2 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2026-82329 が悪用されました: JFrog Artifactory 管理者の乗っ取り CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover #DailyCyberSecurity (Sep 1) https://t.co/GmZWOkhUMl

    @foxbook

    2 Sept 2026

    222 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. JFrog Artifactoryの脆弱性 CVE-2026-82329、認証なしで管理者権限取得のおそれ 実悪用報告、Self-Hostedは更新を https://t.co/lipBjJGTNm #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    2 Sept 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. PaperCut NG/MF zero-days (CVE-2026-82078, CVE-2026-81578) are now in CISA KEV and driving data theft, while JFrog Artifactory auth bypass CVE-2026-82329 is under active exploitation days after disclosure. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1RTfujYNTK

    @itsalreadywhen

    1 Sept 2026

    69 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  25. 🔴 Kritik JFrog Artifactory açığı: CVE-2026-82329 JFrog Artifactory'de keşfedilen CVSS 9.8 seviyesindeki kritik güvenlik açığı, varsayılan yapılandırmada kimlik doğrulaması olmayan bir saldırganın ağ üzerinden yönetici yetkileri elde etmesine neden olabiliy

    @ridvanyagli

    1 Sept 2026

    669 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  26. 🐦 🚨 Actively exploited today: PaperCut NG/MF flaws now in CISA KEV (data theft), Langflow CVE-2026-0768 (CVSS 9.8) + Rails CVE-2026-66066 under mass exploitation, and JFrog Artifactory auth-bypass CVE-2026-82329 hit in-the-wild. Patch now. #infosec #CVE #0day

    @ita_ipo

    1 Sept 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨🚨🚨 『under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.』 Severity: Critical JFrog Artifactory contains an authentication weakness... · CVE-2026-82329 · GitHub Advisory Database https://t.co/v

    @autumn_good_35

    1 Sept 2026

    366 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  28. Auth bypass in JFrog Artifactory CVSS 9.8 CVE-2026-82329 默认配置、不用登录、网络能摸到就能拿管理员。 制品库被拿 = 投毒整条供应链。 自查: 自建看版本,对号入座升 7.111.21 / 7.117.28 / 7.125.20 7.133.29 / 7.146.38 / 7.161.20 JFr

    @ckcsec

    31 Aug 2026

    442 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory. It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale. It affects default configs, requires no auth, no user interaction. It’s an RCE b

    @rauchg

    30 Aug 2026

    394329 Impressions

    200 Retweets

    2680 Likes

    1046 Bookmarks

    122 Replies

    69 Quotes

Configurations