CVE-2026-82329
Published Aug 28, 2026
Last updated 10 days ago
AI description
CVE-2026-82329 describes an authentication weakness found in JFrog Artifactory. Under its default configuration, this vulnerability allows an unauthenticated attacker with network access to gain administrative privileges. This flaw is present in various versions of JFrog Artifactory, including those before 7.111.21, and specific ranges within 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36/37, and 7.161.0 through 7.161.19.
- Description
- JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
- Source
- reefs@jfrog.com
- NVD status
- Analyzed
- Products
- artifactory
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- JFrog Artifactory Improper Authentication Vulnerability
- Exploit added on
- Sep 2, 2026
- Exploit action due
- Sep 5, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- reefs@jfrog.com
- CWE-287
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
8
🚨 JFROG ARTIFACTORY UNDER ACTIVE ATTACK — AUTH BYPASS LEADS TO ADMIN CONTROL AND BACKDOORS Wiz Research has confirmed active in-the-wild exploitation of THREE vulnerabilities affecting self-hosted JFrog Artifactory environments: * CVE-2026-82329 — Critical authentication
@DailyDarkWeb
13 Sept 2026
4552 Impressions
1 Retweet
18 Likes
4 Bookmarks
0 Replies
0 Quotes
Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.
@Sunil_kumawat17
11 Sept 2026
71 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42
@rst_cloud
11 Sept 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB
@yactina1336
10 Sept 2026
62 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 JFrog Artifactory Authentication Bypass (CVE-2026-82329) Exploited in the Wild Critical Vulnerability Alert! JFrog Artifactory is affected by CVE-2026-82329. 🔍 Identify Targets via ZoomEye: Search Dork: app="JFrog Artifactory" Exposure: 17.9k instances identified globa
@zoomeyebot
10 Sept 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV: CVE-2026-82329 JFrog Artifactory improper auth. Default config can give unauthenticated admin access. Active exploitation confirmed in Sep 2 catalog update. #cybersecurity #infosec #CISA #KEV #Artifactory https://t.co/k0Sha2yMEB
@Caldura7
7 Sept 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV listing for JFrog Artifactory (CVE-2026-82329) confirms active exploitation. A 9.8 CVSS is notable, but the key is the default config allowing unauth admin access. Check your Artifactory instances for non-default auth settings immediately.
@BytesNora
5 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Chrome patched an actively exploited V8 0-day (CVE-2026-85046) — update now. JFrog Artifactory auth bypass (CVE-2026-82329, CVSS 9.8) is being exploited to forge admin tokens. SonicWall SMA1000 bugs (CVSS 10.0) just hit CISA's KEV list. #infosec #CVE #0day
@ita_ipo
4 Sept 2026
92 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CYBER — Une faille critique de JFrog Artifactory est désormais activement exploitée. La vulnérabilité CVE-2026-82329, notée CVSS 9,8/10, permet à un attaquant non authentifié ayant accès au service de contourner l’authentification et d’obtenir des privilèges
@ActuX_off
4 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Fastly Threat Research team is tracking a sharp escalation in exploitation attempts for CVE-2026-82329, a critical authentication bypass in self-hosted JFrog Artifactory. Since its disclosure on August 28, we’ve observed activity surge from low-level probing to opportunisti
@fastly
4 Sept 2026
906 Impressions
0 Retweets
4 Likes
1 Bookmark
1 Reply
0 Quotes
A CVSS 9.8 just turned build servers into admin keys. CVE-2026-82329: an unauthenticated attacker forges admin tokens in JFrog Artifactory. Already exploited in the wild. On CISA's KEV list as of Sept 2. The scary part isn't the CVE. It's the blast radius 🧵 https://t.co/04sz
@fiks_cloud
3 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🐦 🚨 SonicWall SMA1000 zero-days (CVE-2026-83548, CVSS 10.0 + CVE-2026-83549) chained for unauth RCE, actively exploited, added to CISA KEV. JFrog Artifactory CVE-2026-82329 (CVSS 9.8) also exploited itw — forges admin tokens. Patch now. #infosec #CVE #0day
@ita_ipo
3 Sept 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA adds seven actively exploited flaws to the KEV catalog, including two in SonicWall SMA1000, one in JFrog Artifactory and one in Kestra OSS. CVE-2026-83548 enables unauthenticated SSRF while CVE-2026-83549 allows OS command execution. CVE-2026-82329 grants remote admin
@WorldCyberNewsX
3 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Exploitation windows continue to shrink. The recent JFrog Artifactory authentication bypass (CVE-2026-82329) saw in-the-wild use just days after disclosure. Continuous vulnerability monitoring and prioritized patching of supply-chain tools are now essential.
@Lumideezy
3 Sept 2026
95 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
1/5 A critical Artifactory flaw was patched on August 28. Days later, watchTowr observed attackers exploiting it to mint admin tokens. CVE-2026-82329 is an unauthenticated auth bypass affecting self-hosted deployments under default configuration. 🧵 https://t.co/mOaQrJw4v8
@SOCMinute
2 Sept 2026
15 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
تجاوز المصادقة دون تسجيل دخول في JFrog Artifactory يستحق فهماً عملياً، لا قراءة سطحية فقط. يتناول المحتوى CVE-2026-82329 من زاوية قابلة لإعادة الاختبار عبر Docker lab، مع PoC
@fad_777
2 Sept 2026
72 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
✅ CALLED IT — CVE-2026-82329 just landed in the CISA #KEV catalog. ThreatClaw's AI agents flagged this 5 days before CISA listed it. That's 1 confirmed KEV calls — and counting. See what's predicted next 👇 https://t.co/HYMvDH8ply #CyberSecurity #ThreatIntelligence #CV
@XManinderSingh
2 Sept 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
✅ CALLED IT — CVE-2026-82329 just landed in the CISA #KEV catalog. ThreatClaw's AI agents flagged this 5 days before CISA listed it. That's 32 confirmed KEV calls — and counting. See what's predicted next 👇 https://t.co/HYMvDH8ply #CyberSecurity #ThreatIntelligence #C
@XManinderSingh
2 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 JFrog Artifactory Açığı Aktif İstismarda CVE-2026-82329 (CVSS 9.8), kimlik doğrulaması olmadan saldırganların yönetici yetkisi kazanmasına izin veriyor. Açık yayınlandıktan sadece birkaç gün sonra istismar edilmeye başlandı. #CVE #CyberSecurity http
@KubbeSiber
2 Sept 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Most CISOs I work with underestimate how fast attackers exploit disclosed vulnerabilities. JFrog Artifactory’s critical CVE-2026-82329 was weaponized within days of public patch release. #CyberSecurity #InfoSec #VAPT
@ThreatRix_Ai
2 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass. https://t.co/jebAYcLQ8L #ThreatIntel #CVE_2026_82329 #watchTowr https://t.co/5YGBBBq3KK
@threadlinqs
2 Sept 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-82329 が悪用されました: JFrog Artifactory 管理者の乗っ取り CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover #DailyCyberSecurity (Sep 1) https://t.co/GmZWOkhUMl
@foxbook
2 Sept 2026
222 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JFrog Artifactoryの脆弱性 CVE-2026-82329、認証なしで管理者権限取得のおそれ 実悪用報告、Self-Hostedは更新を https://t.co/lipBjJGTNm #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
@securityLab_jp
2 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut NG/MF zero-days (CVE-2026-82078, CVE-2026-81578) are now in CISA KEV and driving data theft, while JFrog Artifactory auth bypass CVE-2026-82329 is under active exploitation days after disclosure. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1RTfujYNTK
@itsalreadywhen
1 Sept 2026
69 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
🔴 Kritik JFrog Artifactory açığı: CVE-2026-82329 JFrog Artifactory'de keşfedilen CVSS 9.8 seviyesindeki kritik güvenlik açığı, varsayılan yapılandırmada kimlik doğrulaması olmayan bir saldırganın ağ üzerinden yönetici yetkileri elde etmesine neden olabiliy
@ridvanyagli
1 Sept 2026
669 Impressions
0 Retweets
6 Likes
2 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Actively exploited today: PaperCut NG/MF flaws now in CISA KEV (data theft), Langflow CVE-2026-0768 (CVSS 9.8) + Rails CVE-2026-66066 under mass exploitation, and JFrog Artifactory auth-bypass CVE-2026-82329 hit in-the-wild. Patch now. #infosec #CVE #0day
@ita_ipo
1 Sept 2026
105 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 『under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.』 Severity: Critical JFrog Artifactory contains an authentication weakness... · CVE-2026-82329 · GitHub Advisory Database https://t.co/v
@autumn_good_35
1 Sept 2026
366 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Auth bypass in JFrog Artifactory CVSS 9.8 CVE-2026-82329 默认配置、不用登录、网络能摸到就能拿管理员。 制品库被拿 = 投毒整条供应链。 自查: 自建看版本,对号入座升 7.111.21 / 7.117.28 / 7.125.20 7.133.29 / 7.146.38 / 7.161.20 JFr
@ckcsec
31 Aug 2026
442 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory. It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale. It affects default configs, requires no auth, no user interaction. It’s an RCE b
@rauchg
30 Aug 2026
394329 Impressions
200 Retweets
2680 Likes
1046 Bookmarks
122 Replies
69 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "228ED2A9-1A54-49E2-9F04-1BC7050280E1",
"versionEndExcluding": "7.111.21",
"versionStartIncluding": "7.111.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "42B6DAA5-F4C7-42AC-9CE3-D2A653499DA7",
"versionEndExcluding": "7.117.28",
"versionStartIncluding": "7.117.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "CFA2D1EB-856D-4001-8236-E4C98CD0CCCC",
"versionEndExcluding": "7.125.20",
"versionStartIncluding": "7.125.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "A498A09A-B194-4D5C-8D30-6A388BE2D496",
"versionEndExcluding": "7.133.29",
"versionStartIncluding": "7.133.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "B9CD84FD-5435-440E-AFE3-7EB20FD5D723",
"versionEndExcluding": "7.146.38",
"versionStartIncluding": "7.146.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "1D77FF33-5D0D-4A15-B7A7-07ADD5C96883",
"versionEndExcluding": "7.161.20",
"versionStartIncluding": "7.161.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]