Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "authentication-bypass", "jfrog", "artifactory", "supply-chain"] ยท confidence: high ยท severity: critical ยท affected_sectors: ["Technology", "Government", "Defence"] ยท au_impact: true

CVE-2026-82329

Affected product: JFrog Artifactory (self-managed) โ€” unauthenticated authentication bypass

Patched version: Patched 2026-08-28 across multiple versions (7.161.20 and earlier)

Active exploitation: Yes โ€” actively exploited in the wild; added to CISA KEV on 2026-09-02

Assessment

A critical authentication-bypass flaw in self-managed JFrog Artifactory is being exploited in the wild, with watchTowr observing attackers minting admin tokens on effectively default configurations. An unauthenticated attacker with network access can gain administrative privileges, enumerate users, read artifacts, change security configuration and poison packages trusted by downstream build and deployment systems. JFrog patched on 28 August, but access tokens persist independent of the upgrade, so any already-forged admin token survives binary patching and should be rotated; Australian firms running self-hosted Artifactory should treat the KEV addition as urgent given the package-poisoning supply-chain risk to APRA CPS 234 and ASD Essential Eight-controlled build environments.