PT-2026-83316 · Jfrog · Artifactory
CVE-2026-82329
·
Published
2026-08-28
·
Updated
2026-09-12
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JFrog Artifactory versions prior to 7.111.21
JFrog Artifactory versions prior to 7.117.28
JFrog Artifactory versions prior to 7.125.20
JFrog Artifactory versions prior to 7.133.29
JFrog Artifactory versions prior to 7.146.38
JFrog Artifactory versions prior to 7.161.20
Description
JFrog Artifactory contains an authentication weakness in the JFrog Access component, which handles authentication and credentialing. Under default configurations, an unauthenticated attacker with network access can bypass the authentication boundary to obtain administrative privileges. This is achieved by abusing the behavior of the join key; specifically, instances without an additional join key may use a predictable service key, allowing an attacker to forge access and mint administrator tokens.
Real-world exploitation has been reported, with attackers using the flaw to enumerate users, groups, and federated-access topology. Because Artifactory manages critical software supply chain assets—including container images, npm and Python packages, Maven artifacts, and AI models—administrative compromise allows for potential artifact manipulation, credential theft, and the distribution of malicious software to downstream CI/CD pipelines and production environments.
Recommendations
Upgrade to version 7.111.21 or the applicable fixed release for the respective branch.
Upgrade to version 7.117.28 or the applicable fixed release for the respective branch.
Upgrade to version 7.125.20 or the applicable fixed release for the respective branch.
Upgrade to version 7.133.29 or the applicable fixed release for the respective branch.
Upgrade to version 7.146.38 or the applicable fixed release for the respective branch.
Upgrade to version 7.161.20 or the applicable fixed release for the respective branch.
Restrict network exposure of Artifactory to trusted networks only.
Review recently created administrator accounts and tokens, and audit authentication events for unusual user or group enumeration.
Rotate high-value credentials and validate the integrity of repositories and build artifacts if a compromise is suspected.
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artifactory