Skip to main content
QUIETLYTIC
Vulnerability

JFrog Artifactory Authentication Bypass (CVE-2026-82329)

CVE-2026-82329 is a CVSS 9.8 authentication flaw letting an unauthenticated attacker gain JFrog Artifactory admin rights. Added to CISA KEV Sept. 2, 2026.

CVE-2026-82329
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
JFrog Artifactory

CVE-2026-82329 is the most severe of four JFrog Artifactory vulnerabilities that CISA has added to its Known Exploited Vulnerabilities catalog since late August 2026. NVD scores it 9.8 (critical) under CWE-287 (Improper Authentication) and records the September 2, 2026 KEV addition; per NVD, Artifactory contains an authentication weakness that, under default configuration, may let an unauthenticated attacker with network access obtain administrative privileges.

What the flaw is

The operative phrase in NVD’s record is “under default configuration.” Most authentication failures worth this score require a specific deployment mistake to become exploitable — an exposed management port, a disabled control, a credential left at its shipped value. This one, as NVD describes it, does not. An Artifactory instance installed and run as shipped is the vulnerable case, which means the population of affected deployments is not bounded by how carefully an operator hardened the product.

NVD’s description is unusually terse, and that constrains what can honestly be said about mechanism. The record names the weakness class (CWE-287), the precondition (network access, no authentication), and the outcome (administrative privileges). It does not state which authentication control fails or how, and no second ingested source fills that gap. We are not going to reconstruct the mechanism from inference — the CWE and the outcome are the supported claims.

Four Artifactory CVEs, one three-week window

Our own ingested KEV data shows a cluster rather than an isolated advisory. Ordered by severity:

CVE CVSS CWE KEV added Coverage
CVE-2026-82329 9.8 CWE-287 Sept. 2, 2026 This article
CVE-2026-42016 8.1 — Sept. 11, 2026 Published
CVE-2026-42018 7.5 CWE-287 Sept. 11, 2026 Published
CVE-2026-66384 5.3 — Aug. 27, 2026 Not yet covered

Two points follow from the table. First, this CVE shares its CWE-287 classification with CVE-2026-42018 but outranks it by 2.3 CVSS points, and it reached KEV nine days earlier — so an organisation that patched in response to the widely-covered September 11 pair may have a false sense of completeness if it did not also address the September 2 addition. Second, four CVEs against one product inside sixteen days — two of them sharing a CWE, two of them sharing a KEV date — is a configuration in which advisories are easy to transpose. They are four distinct records with distinct scores and distinct KEV dates. Map each patch to a CVE identifier rather than to a vendor name or a headline, or the highest-severity item in the cluster is the one most likely to be recorded as already handled.

Evidence and confidence

  • High confidence — exploitation status and the September 2 KEV date, corroborated by both CISA’s catalog and VulnCheck’s KEV feed. The CWE-287 classification is triple-sourced across NVD, CISA KEV, and VulnCheck KEV.
  • Medium confidence — the CVSS 9.8 score, the vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the description, including the “default configuration” qualifier. These trace to NVD alone in our provenance data. No source contradicts them; none corroborates them either.
  • Unknown — exploitation probability. No EPSS score has been ingested for this CVE.

No field in this record is in conflict between sources. Our data carries no affected-version range and no fixed release; JFrog’s own security advisories and self-managed release notes are the authoritative references, both of which NVD links from this record.

Why this matters

Artifactory is a binary repository — the place build artifacts, container images, and internal packages are stored and served to CI pipelines and developer machines. Administrative control over it is therefore not equivalent to administrative control over an ordinary application server. An attacker holding admin on a build-artifact repository sits upstream of everything that repository feeds, which puts this in software-supply-chain territory: the blast radius extends to consumers of the artifacts, not just the host.

That is what elevates this above its already-critical score. CVSS records scope as unchanged (S:U), a technically correct statement about the vulnerability’s immediate reach that understates the operational consequence of the asset it applies to. Combined with confirmed exploitation, a default-configuration precondition, and the position Artifactory occupies in a build chain, this belongs at the front of the patch queue for any self-managed deployment — ahead of the two September 11 siblings, despite those having received more attention.

For US federal civilian agencies, the KEV listing carries a remediation obligation under Binding Operational Directive 26-04. CISA’s entry directs stakeholders to apply vendor mitigations under that directive, to evaluate each asset’s internet exposure, and to discontinue use where no mitigation is available.

Frequently Asked Questions

What is CVE-2026-82329? A CVSS 9.8 improper-authentication vulnerability (CWE-287) in JFrog Artifactory that, per NVD, may allow an unauthenticated attacker with network access to obtain administrative privileges under the product’s default configuration.

Is CVE-2026-82329 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, 2026, and VulnCheck’s KEV feed independently records the same date and exploitation status.

Is this the same as the JFrog Artifactory CVEs added to KEV on September 11? No. CVE-2026-42016 (8.1) and CVE-2026-42018 (7.5) are separate records added nine days later. CVE-2026-82329 is the more severe flaw and was catalogued first; patching the September 11 pair does not address it.

Does disabling anonymous access mitigate CVE-2026-82329? Our ingested source data does not say. NVD describes the weakness as present under default configuration but names no vendor workaround, and we will not infer one — consult JFrog’s security advisories for any interim mitigation. Note that a related Artifactory flaw, CVE-2026-42018, specifically involved anonymous-token issuance continuing despite anonymous access being disabled, so that control should not be assumed sufficient for either CVE.

Which versions of Artifactory are affected? No affected-version range or fixed release is present in our ingested data. JFrog’s self-managed release notes and security advisories are authoritative.

Why does a CVSS scope of “unchanged” still amount to supply-chain risk? Scope in CVSS describes whether exploitation crosses a security boundary within the vulnerable system, not how important that system is. Artifactory feeds build pipelines, so administrative control over it affects downstream artifact consumers even though the vulnerability itself stays within the appliance.


Severity, vector, weakness classification, and description sourced from the National Vulnerability Database record for CVE-2026-82329; exploitation status, KEV date, and remediation guidance from the CISA Known Exploited Vulnerabilities catalog, with corroborating exploitation status from VulnCheck’s KEV feed. Vendor references: JFrog security advisories and Artifactory self-managed release notes. Aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools