Critical Authentication Vulnerability in JFrog Artifactory (CVE-2026-82329)

Critical Authentication Vulnerability in JFrog Artifactory (CVE-2026-82329)

First seen 29 Aug 2026, 16:45 UTC Feedlystemshop.topwww.thehackerwire.comvuldb.com 74.0

Article Content

Browse articles
ThreatCluster

JFrog Artifactory has a critical authentication vulnerability (CVE-2026-82329) that allows unauthenticated attackers with network access to gain administrative privileges under default configurations. This flaw has a CVSS score of 9.8, indicating a high severity. Currently, there are no public proof-of-concept exploits or confirmed instances of exploitation. Organizations using affected versions are advised to apply patches immediately and review their configuration settings to enforce strong authentication. Monitoring of authentication logs for suspicious activities is also recommended. The vulnerability affects all instances of JFrog Artifactory running with default settings. As of now, there is no evidence of exploitation in the wild or public proof-of-concept code available. The first details of this vulnerability were published on August 28, 2026.

Key Points: • CVE-2026-82329 allows unauthenticated access to JFrog Artifactory. • The vulnerability has a CVSS score of 9.8, indicating critical severity. • No public exploits or confirmed exploitation have been reported yet.

Timeline

2026-08-28
CVE-2026-82329 published
JFrog disclosed a critical authentication vulnerability in Artifactory affecting default configurations.
stemshop.top
2026-08-29
Security advisory released
JFrog and other sources advised immediate patching and configuration review to mitigate the vulnerability.
Feedly