CVE-2026-82329
JFrog Artifactory authentication bypass can grant unauthenticated admin access (CVE-2026-82329)
JFrog Artifactory has an authentication weakness that, under default configuration, may let an unauthenticated network attacker gain administrative privileges. CISA records active exploitation. Fixed releases are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.
What happened
JFrog Artifactory contains an authentication weakness (CWE-287). Under default configuration, an attacker with network access to the service can obtain administrative privileges without any prior credentials and with no action required from a legitimate user. The CVSS 3.1 score is 9.8, rated critical; the vector describes network reachability, low attack complexity, no privileges, no user interaction, unchanged scope and high impact on confidentiality, integrity and availability.
CISA has listed the vulnerability in its Known Exploited Vulnerabilities catalogue and its SSVC assessment records active exploitation. No vendor advisory was included in this record, and no public disclosure is recorded.
Who is affected
The affected product is JFrog Artifactory. Versions affected are: before 7.111.21; 7.117.0 to before 7.117.28; 7.125.0 to before 7.125.20; 7.133.0 to before 7.133.29; 7.146.0 to before 7.146.38; and 7.161.0 to before 7.161.20. If you run Artifactory on a network segment reachable from untrusted clients, treat the instance as affected until it is upgraded.
What to do now
- Upgrade to a fixed release: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20, according to your release line.
- Apply the upgrade promptly. CISA added this vulnerability to KEV with a due date of 2026-09-05; the required action is to apply mitigations and, if mitigations are unavailable, discontinue use of the product. If you cannot upgrade immediately, follow the containment step below.
- Restrict network access to Artifactory so it is not reachable from untrusted networks.
- After upgrading, review administrative accounts and configuration for unauthorised changes.
How to detect it
No vendor or CISA indicators are provided in this record. Focus on the exposure itself: identify every Artifactory instance reachable from untrusted networks, and review administrative accounts for unexpected additions or permission changes.
Beyond the patch
Because CISA records active exploitation and the weakness is reachable over the network without credentials, any exposed Artifactory should be treated as potentially compromised until verified. Managed Detection & Response can help detect post-exploitation activity, and Virtual CISO Services can turn exposed services and missing patches into a measured, reportable exposure programme rather than ad hoc firefighting.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| artifactory | – < 7.111.21 7.117.0 – < 7.117.28 7.125.0 – < 7.125.20 7.133.0 – < 7.133.29 7.146.0 – < 7.146.38 7.161.0 – < 7.161.20 | 7.111.21 7.117.28 7.125.20 7.133.29 7.146.38 7.161.20 |