Threat Advisory

Artifactory Flaw Bypasses Authentication Granting Admin Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-82329 is a critical improper authentication vulnerability affecting JFrog Artifactory and carries a CVSS score of 9.8. The vulnerability may allow an unauthenticated attacker with network access to bypass authentication and obtain administrative privileges under the default configuration. Successful exploitation could result in complete administrative control of the affected Artifactory instance. Attackers may potentially access sensitive artifacts, repositories, credentials, and other resources managed by the platform. The vulnerability requires no authentication or user interaction, making it particularly dangerous for exposed instances. Affected versions include Artifactory versions before 7.111.21, versions 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.37, and 7.161.0 through 7.161.19. The vulnerability impacts confidentiality, integrity, and availability at a high level and could enable attackers to compromise the software supply chain managed through the affected Artifactory environment.

RECOMMENDATION:

We recommend you to update JFrog Artifactory to version 7.161.20, 7.146.38, 7.133.29, 7.125.20, or 7.117.28.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-82329 is a critical improper authentication vulnerability affecting JFrog Artifactory and carries a CVSS score of 9.8. The vulnerability may allow an unauthenticated attacker with network access to bypass authentication and obtain administrative privileges under the default configuration. Successful exploitation could result in complete administrative control of the affected Artifactory instance. Attackers may potentially access sensitive artifacts, repositories, credentials, and other resources managed by the platform. The vulnerability requires no authentication or user interaction, making it particularly dangerous for exposed instances. Affected versions include Artifactory versions before 7.111.21, versions 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.37, and 7.161.0 through 7.161.19. The vulnerability impacts confidentiality, integrity, and availability at a high level and could enable attackers to compromise the software supply chain managed through the affected Artifactory environment.

RECOMMENDATION:

We recommend you to update JFrog Artifactory to version 7.161.20, 7.146.38, 7.133.29, 7.125.20, or 7.117.28.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu