Critical JFrog Artifactory Flaw Under Active Exploitation: Authentication Bypass Grants Admin Access
A critical authentication bypass vulnerability, **CVE-2026-82329**, affecting **JFrog Artifactory** is now under active exploitation, mere days after public disclosure. This flaw could allow unauthenticated attackers to gain administrative privileges, posing a severe threat to software supply chains.
Threat actors are actively exploiting a newly patched critical security flaw impacting **JFrog Artifactory**, according to recent reports. This rapid weaponization follows closely on the heels of the vulnerability's public disclosure.
The vulnerability, identified as **CVE-2026-82329** (CVSS score: 9.8), is an authentication bypass that can lead to administrative access within Artifactory instances.
"**JFrog Artifactory** contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges," states the description on CVE.org.
**JFrog** addressed the vulnerability with **Artifactory version 7.161.20**, released on August 28, 2026. The flaw impacts several earlier versions:
* 7.161.0 > 7.161.19
* 7.146.0 > 7.146.36
* 7.133.0 > 7.133.28
* 7.125.0 > 7.125.19
* 7.117.0 > 7.117.27
* 7.111.4 > 7.111.21
**Vercel** CEO **Guillermo Rauch** highlighted the severity on LinkedIn, noting, "It affects default configs, requires no auth, no user interaction. It's an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that."
The root of the issue lies within **JFrog Access**, the component responsible for issuing and validating credentials. **Yordan Ganchev**, Principal Threat Intelligence Specialist at **watchTowr**, explained that "Instances without an additional join key configured receive a 'phantom' join key that attackers can abuse to forge access and mint administrator-level credentials."
**Ganchev** confirmed that threat actors began weaponizing the flaw as early as September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies.
"This moved from disclosure to real-world exploitation with uncomfortable efficiency," **Ganchev** added. "Anyone following along knows what comes next: things will get worse."
Attackers gaining administrative access to a central software supply chain system can significantly compromise an organization. This allows them to tamper with build pipelines, move laterally into production systems, and potentially push malicious changes downstream to customers.
Organizations operating self-managed versions of **JFrog Artifactory** are strongly advised to apply patches immediately, especially to internet-exposed systems. Additionally, it is critical to inspect audit logs, rotate any exposed credentials, and thoroughly review connected systems for signs of malicious changes or backdoor access.
