PT-2026-83316 · Jfrog · Artifactory

CVE-2026-82329

·

Published

2026-08-28

·

Updated

2026-09-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.111.21 JFrog Artifactory versions prior to 7.117.28 JFrog Artifactory versions prior to 7.125.20 JFrog Artifactory versions prior to 7.133.29 JFrog Artifactory versions prior to 7.146.38 JFrog Artifactory versions prior to 7.161.20
Description JFrog Artifactory contains an authentication weakness in the JFrog Access component, which handles authentication and credentialing. Under default configurations, an unauthenticated attacker with network access can bypass the authentication boundary to obtain administrative privileges. This is achieved by abusing the behavior of the join key; specifically, instances without an additional join key may use a predictable service key, allowing an attacker to forge access and mint administrator tokens.
Real-world exploitation has been reported, with attackers using the flaw to enumerate users, groups, and federated-access topology. Because Artifactory manages critical software supply chain assets—including container images, npm and Python packages, Maven artifacts, and AI models—administrative compromise allows for potential artifact manipulation, credential theft, and the distribution of malicious software to downstream CI/CD pipelines and production environments.
Recommendations Upgrade to version 7.111.21 or the applicable fixed release for the respective branch. Upgrade to version 7.117.28 or the applicable fixed release for the respective branch. Upgrade to version 7.125.20 or the applicable fixed release for the respective branch. Upgrade to version 7.133.29 or the applicable fixed release for the respective branch. Upgrade to version 7.146.38 or the applicable fixed release for the respective branch. Upgrade to version 7.161.20 or the applicable fixed release for the respective branch. Restrict network exposure of Artifactory to trusted networks only. Review recently created administrator accounts and tokens, and audit authentication events for unusual user or group enumeration. Rotate high-value credentials and validate the integrity of repositories and build artifacts if a compromise is suspected.

Fix

RCE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82329

Affected Products

Artifactory