← Vulnerability feed

Vulnerability record · CVE-2026-82329 · published 28 August 2026

CVE-2026-82329: JFrog Artifactory improper authentication allows admin takeover

Jfrog · Artifactory

JFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with network access obtain administrative privileges. Because the flaw is reachable without credentials and grants full admin rights, it is a severe risk to any exposed instance. The record does not specify which versions are affected.

9.8 CVSS 3.1 Critical CISA KEV since 2 Sep 2026 EPSS 14% · top 3.5% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
3 Sep 2026Last modified by NVD

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable flaw yielding administrative privileges, rated CVSS 9.8 and listed in CISA KEV as exploited.

What it is

JFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with network access obtain administrative privileges. Because the flaw is reachable without credentials and grants full admin rights, it is a severe risk to any exposed instance. The record does not specify which versions are affected.

Impact

An attacker gains administrative control of the Artifactory instance, which can expose stored artifacts, credentials and build pipeline data and allow tampering with the software supply chain. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), so any internet- or network-exposed Artifactory endpoint is a candidate target. The description ties the weakness to default configuration, meaning unhardened deployments are the primary exposure.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2026-09-02, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.07666 (94.3rd percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor fix from the JFrog security advisories and release notes; CISA's KEV due date was 2026-09-05, so treat patching as urgent.
  • If no patch is available for your version, follow CISA BOD 26-04 guidance for cloud services or discontinue use of the product.
  • Remove Artifactory from direct internet exposure and restrict network access to trusted management networks until patched.
  • Review and harden default authentication configuration, and rotate administrative credentials and tokens after remediation.
  • Audit for unauthorized admin accounts, configuration changes and anomalous artifact activity.

Detection

  • Hunt for authentication events that result in admin-level access from unauthenticated or unexpected source IPs.
  • Alert on creation of new administrative users, API keys or tokens outside change windows.
  • Monitor for configuration changes to authentication and security settings in Artifactory logs.
  • Correlate network access to Artifactory endpoints from external or untrusted ranges with subsequent privileged actions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "JFrog Artifactory Improper Authentication Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-82329 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2022-0668Jfrog artifactory improper privilege management vulnerabilityJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is…EPSS 0.63%9.8CVE-2019-17444JFrog Artifactory default admin passwords allow full compromiseJFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials …EPSS 69%analysed9.8CVE-2018-19971Jfrog artifactory insufficient verification of data authenticity vulnerabilityJFrog Artifactory Pro 6.5.9 has Incorrect Access Control.EPSS 3.0%9.8CVE-2019-9733JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-ForArtifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For…EPSS 53%analysed9.8CVE-2016-10036Jfrog artifactory unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…EPSS 26%

Source: NIST National Vulnerability Database (record CVE-2026-82329), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.