CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Other sources
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
— CISA
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Artifactory instances reachable by an unauthenticated attacker over the network are exposed. The issue may occur under the default configuration.
What does an attacker need to exploit it?
An attacker needs network access to the affected Artifactory instance. No prior authentication, privileges, or user interaction are required.
What could successful exploitation allow?
Successful exploitation may allow the attacker to obtain Artifactory administrative privileges. The listed impact includes high confidentiality, integrity, and availability impact.