Critical

JFrog, Artifactory, CVE-2026-82329, Auth Bypass, Supply Chain, Exploited

JFrog Artifactory CVE-2026-82329: Admin Bypass Exploited

JFrog Artifactory CVE-2026-82329 is a CVSS 9.8 unauthenticated auth bypass to admin, exploited days after disclosure via a phantom join key. Fix and exposure.

JFrog Artifactory CVE-2026-82329 is a critical authentication bypass (CVSS 9.8, CWE-287) that, under default configuration, lets an unauthenticated attacker with network access obtain administrator privileges, and attackers began exploiting it on September 1, 2026, just days after disclosure. watchTowr reports that threat actors are already using it to mint administrator tokens and enumerate users, groups, credential sets, and federated access topologies. Because Artifactory hosts the binaries and packages that feed software builds, admin access is a supply-chain compromise waiting to happen, which is why one observer called it an RCE bomb: poison the artifacts and you poison everything downstream.

The flaw lives in JFrog Access, the component that issues and validates credentials. According to watchTowr, instances without an additional join key configured receive a phantom join key that attackers can abuse to forge access and mint administrator-level credentials. It affects default configurations, requires no authentication, and needs no user interaction, the combination that turns a newly disclosed flaw into mass exploitation within days. JFrog patched it in Artifactory 7.161.20, released August 28, 2026.

Which Artifactory versions are affected and how do I fix it?

Multiple release trains are affected, and the fix is to upgrade to a patched build (7.161.20 or the corresponding fixed release in your train). Given active exploitation and the fact that the default configuration is vulnerable, this should be treated as an emergency patch, and instances should be checked for signs of forged admin tokens and unexpected user or group enumeration.

Item

Detail

CVE

CVE-2026-82329 (CVSS 9.8, CWE-287 auth bypass)

Root cause

JFrog Access issues a phantom join key when none is configured

Impact

Unauthenticated attacker mints admin credentials

Affected

7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, 7.111.4-7.111.21

Fixed in

Artifactory 7.161.20 (released 2026-08-28)

Exploitation

In the wild since 2026-09-01 (watchTowr)

Why it matters

Artifactory hosts build artifacts, so admin access poisons the supply chain

Why is an artifact repository a supply-chain crown jewel?

Because everything downstream trusts it. Artifactory stores the binaries, packages, and dependencies that build and deploy pipelines pull from, so an attacker with admin control can replace or poison artifacts that then flow into production across an entire organization. An authentication bypass to admin is therefore not just a breach of one server, it is a foothold to tamper with the software everyone builds on, which is exactly the leverage supply-chain attackers seek.

Our read

CVE-2026-82329 compresses the disclosure-to-exploitation window to days, against a system that sits at the center of the software supply chain. The specific trap is the default configuration: instances that never set an additional join key are the exposed population, so this is as much a hardening question as a patching one. The verifiable-by-design move is to patch to 7.161.20 now, confirm a real join key is configured, and hunt for forged admin tokens, because an artifact repository compromised quietly is a breach that ships itself into every build.

Reporting by The Hacker News; exploitation and phantom-join-key detail per watchTowr; CVSS and affected versions per NVD, CVE.org, and JFrog. Sources linked above.

Related: Code security for SMBs and How to prioritize vulnerabilities.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.