AI description
CVE-2026-82329 describes an authentication weakness found in JFrog Artifactory. Under its default configuration, this vulnerability allows an unauthenticated attacker with network access to gain administrative privileges. This flaw is present in various versions of JFrog Artifactory, including those before 7.111.21, and specific ranges within 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36/37, and 7.161.0 through 7.161.19.
- Description
- JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
- Source
- reefs@jfrog.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- reefs@jfrog.com
- CWE-287
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
64
Auth bypass in JFrog Artifactory CVSS 9.8 CVE-2026-82329 默认配置、不用登录、网络能摸到就能拿管理员。 制品库被拿 = 投毒整条供应链。 自查: 自建看版本,对号入座升 7.111.21 / 7.117.28 / 7.125.20 7.133.29 / 7.146.38 / 7.161.20 JFr
@ckcsec
31 Aug 2026
442 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory. It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale. It affects default configs, requires no auth, no user interaction. It’s an RCE b
@rauchg
30 Aug 2026
394329 Impressions
200 Retweets
2680 Likes
1046 Bookmarks
122 Replies
69 Quotes