LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 2, 2026
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Sep 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026, with a federal patch deadline of Sep 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

CVE-2026-82329 is an improper authentication weakness in JFrog Artifactory. Under default configuration, an unauthenticated attacker who can reach the product over the network may obtain administrative privileges. That level of access can put artifact repositories, build pipelines, credentials, and downstream software supply chains at risk, so teams that run Artifactory should treat this as a high-priority inventory and remediation item and confirm all version and fix details against the vendor advisory.

CISA describes the issue as allowing unauthenticated network attackers to gain admin rights when the product is left in a default configuration. Known ransomware use is not documented for this CVE. Follow vendor instructions and applicable CISA BOD 26-04 guidance for prioritization and forensics triage.

How it works

The weakness is classified as CWE-287 (Improper Authentication). In this class of flaw, the product does not adequately verify the identity or authorization of a requester before granting privileged access. Per the CISA summary, the vulnerability can, under default configuration, allow an attacker with network access and no prior credentials to obtain administrative privileges on JFrog Artifactory.

In practical terms, that means a remote party who can reach the Artifactory service may be able to bypass normal login or privilege checks and operate with admin-level control. Exact request paths, configuration knobs, and exploit mechanics are not provided here; defenders must not assume attack details and should rely on the vendor advisory for precise technical description. Administrative control of an artifact repository typically implies the ability to alter packages, access tokens or secrets stored for CI/CD, change permissions, and influence what is distributed to build and runtime environments—so the blast radius extends beyond the Artifactory host itself.

Am I affected? How to find it in your systems

JFrog Artifactory is commonly deployed as an on-premises or self-managed artifact repository for binaries, containers, and other build outputs, and may also appear in cloud or hybrid setups. It often sits on internal networks but is sometimes exposed to broader corporate networks or the internet for remote teams and automation.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation package named in the official advisory for CVE-2026-82329, and verify the fixed build is running in each environment (dev, test, production, DR).

If you can't patch immediately

Reduce exposure until the vendor fix is installed.

If your data may have been exposed

Actively exploited authentication flaws can lead to full administrative compromise and follow-on theft or tampering of artifacts, secrets, and connected systems. If Artifactory was reachable in a vulnerable state, assume possible credential and package integrity impact: rotate secrets, invalidate tokens, audit published artifacts, and investigate downstream build systems. Known ransomware use is not documented for this CVE, but that does not rule out other misuse. As a simple personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their identities appear in unrelated public breach corpora while the organization completes formal incident review.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedJFrog · Artifactory
WeaknessCWE-287
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedAug 28, 2026
Added to CISA KEVSep 2, 2026
Federal patch deadlineSep 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities