JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under default configuration. JFrog patched the flaw in Artifactory 7.161.20 on August 28, 2026, and the issue affects multiple self-managed release lines. The weakness sits in JFrog Access, where attackers can abuse credential-handling logic to mint admin-level access.
Related Happenings
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
How related:
"Ganchev also pointed out that threat actors have begun to weaponize the flaw as of September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets and federated access topologies."
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveHow related: "Ganchev also pointed out that threat actors have begun to weaponize the flaw as of September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets and federated access topologies."
About this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
Timeline
-
01.09.2026 20:53 1 articles · 3h ago
JFrog releases Artifactory 7.161.20 to patch CVE-2026-82329
Mitigation Patch UpdateJFrog released Artifactory 7.161.20 on August 28, 2026 to fix CVE-2026-82329, an authentication bypass in JFrog Artifactory that could let an unauthenticated attacker with network access obtain administrative privileges under default configuration. The patch applied to affected self-managed release lines including 7.161.0 through 7.161.19, 7.146.0 through 7.146.36, 7.133.0 through 7.133.28, 7.125.0 through 7.125.19, 7.117.0 through 7.117.27, and 7.111.4 through 7.111.21.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
-
01.09.2026 20:53 2 articles · 3h ago
Threat actors weaponize CVE-2026-82329 to mint admin tokens in JFrog Artifactory
Exploitation ObservedThreat actors had begun weaponizing CVE-2026-82329 by September 1, 2026, using the JFrog Artifactory flaw to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies. The issue sits in JFrog Access, and the reported behavior indicates that unauthenticated network access under default configurations can be turned into administrator-level access.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53