Skip to content
CVE-2026-82329 - Exploits & Severity

CVE-2026-82329 - Exploits & Severity

Feedly August 29, 2026

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

An unauthenticated attacker over the network can bypass authentication to obtain administrative privileges in Artifactory, allowing them to gain full control of the repository system including read, modify, and delete access to all artifacts and configurations.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Apply the available patch immediately. Review Artifactory's default configuration settings and ensure strong authentication mechanisms are enforced. Restrict network access to Artifactory to trusted networks only. Monitor authentication logs for suspicious login attempts or privilege escalation activities.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD published the first details for CVE-2026-82329

Feedly found the first article mentioning CVE-2026-82329 . See article

GitHub Advisories released a security advisory .

A critical authentication weakness in JFrog Artifactory, with a CVSS score of 9.8, allows unauthenticated attackers with network access to bypass authentication and gain administrative privileges on affected instances running under default configurations. There are currently no public proof-of-concept exploits, patches, or mitigation details available, and organizations are advised to monitor official channels for updates. The vulnerability's impact on non-default configurations and potential downstream effects on third-party technologies remain unaddressed. See article

[GHSA-c5pf-6p5j-gj87] JFrog Artifactory contains an authentication weakness that, under default config

JFrog Artifactory Unauthenticated Admin Access (CVE-2026-82329)

Critical SQLi in IBM Concert 1.0.0-2.3.1

CVE-2026-82329 - Critical CVE & PoC Archive

JFrog Artifactory Unauthenticated Admin Access (CVE-2026-82329)

CVE-2026-82329 | JFrog Artifactory up to 7.161.19 privileges management

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)