Vulnerability
Published 2026-08-28
Verified 2026-09-19

JFrog Artifactory CVE-2026-82329: critical auth bypass; admin-token minting; CISA KEV

JFrog's 28 August 2026 advisory rates CVE-2026-82329 Critical (CVSS 3.1 9.8): under default configuration, an unauthenticated attacker with network access may obtain administrative privileges on self-managed Artifactory. watchTowr told SecurityWeek (1 Sep) and BleepingComputer / The Hacker News (2 Sep) it has seen exploitation — attackers minting admin tokens, enumerating users/groups/federated topologies, and in limited cases creating backdoor users — from a small set of IPs without evidence of mass scanning yet. watchTowr describes a 'phantom' join key on instances without an additional join key configured, abused via JFrog Access to forge administrator credentials. Self-hosted patches: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20; JFrog says cloud was already fortified. Access tokens are independent credentials — upgrading the binary does not by itself revoke minted tokens, so rotate/revoke tokens and hunt anomalous admin activity after patching. CISA added CVE-2026-82329 to the KEV catalog on 2 September 2026. UPDATE 10–11 September 2026 (Wiz / THN): Wiz also saw CVE-2026-82329 abused in the wild alongside a separate 42018→42016 chain (15 Aug–8 Sep) that yields admin and drops Rust C2 / Groovy plugins — see desk cards cve-2026-42018 and cve-2026-42016. Distinct from cve-2026-66384.

Product
JFrog Artifactory
Versions
Self-hosted patches 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20; cloud already rolled out
CVSS
(CVSS 3.1, JFrog CNA)
Exploited in Australia?
unknown
Patch to
Self-hosted: 7.111.21 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.38 / 7.161.20; revoke minted access tokens; hunt admin anomalies

Primary: JFrog security advisories (CVE-2026-82329, 28 Aug 2026) · Vendor: JFrog (vendor) · CVE: CVE-2026-82329, CVE-2026-42018, CVE-2026-42016, CVE-2026-66384 · Wiz — in-the-wild Artifactory chain (10 Sep 2026); also BleepingComputer/watchTowr

vulnerabilities cloud