JFrog Artifactory authentication bypass (CVE-2026-82329) actively exploited days after disclosure
JFrog disclosed a critical authentication bypass in Artifactory on August 28 that lets unauthenticated attackers gain admin access under default settings. Exposure management firm WatchTowr says it has already observed active exploitation, with attackers minting themselves persistent admin tokens. JFrog Ltd $FROG has patched cloud instances automatically; self-hosted customers must update immediately.
JFrog disclosed a critical authentication bypass vulnerability in Artifactory, tracked as CVE-2026-82329, on August 28, 2026. Under the platform's default configuration, an unauthenticated attacker with network access can obtain full administrator privileges with no valid credentials. Exposure management firm WatchTowr says its intelligence team has already observed in-the-wild exploitation, with attackers minting themselves administrator tokens that can persist even after passwords are changed. Artifactory sits inside the software supply chain for many development teams, managing packages, container images, and build dependencies used in CI/CD pipelines. JFrog Ltd $FROG has patched its cloud-hosted instances automatically; companies running Artifactory on their own servers must update to one of six patched versions the company released.