CVE-2026-82329: Potential authentication bypass leading to administrative access in Artifactory
Published Aug 28, 2026
·Updated
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 28, 2026
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Artifactory instances reachable by an unauthenticated attacker over the network are exposed. The issue may occur under the default configuration.
2
What does an attacker need to exploit it?
An attacker needs network access to the affected Artifactory instance. No prior authentication, privileges, or user interaction are required.
3
What could successful exploitation allow?
Successful exploitation may allow the attacker to obtain Artifactory administrative privileges. The listed impact includes high confidentiality, integrity, and availability impact.