Critical Artifactory Bug Under Attack
CVE-2026-82329 is a simple authentication bypass that can allow an attacker to get admin privileges quite easily

CVE-2026-82329 is a simple authentication bypass that can allow an attacker to get admin privileges quite easily
September 2, 2026 | 2 min read

Four days after JFrog released an advisory warning customers about a critical authentication bypass in several versions of its Artifactory package manager, researchers have begun seeing exploitation of the vulnerability in the wild.
JFrog published a series of advisories on Aug. 28 detailing a number of bugs, the most serious of which is CVE-2026-82329, a simple authentication bypass that can allow an attacker to get admin privileges quite easily. The vulnerability affects versions 7.161.0 > 7.161.19, 7.146.0 > 7.146.36, 7.133.0 > 7.133.28, 7.125.0 > 7.125.19, 7.117.0 > 7.117.27, 7.111.4 > 7.111.21 of Artifactory, and JFrog released updates to address the bug in all of them.
The company is encouraging users of affected versions to upgrade as soon as possible, but with exploitation already happening, the opportunity to patch before a vulnerable instance is compromised is fading.
“JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” the advisory says.
On Sept. 1, researchers at watchTowr reported active exploitation of the vulnerability.
“watchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens,” the researchers said.
If you’re snapping your fingers trying to remember where you’ve heard about Artifactory recently, you may be thinking of the July OpenAI-Hugging Face incident in which an OpenAI model that was being tested discovered and exploited zero days in Artifactory as part of its ingenious plan to escape the test environment. However, those vulnerabilities were patched in late July and this new bug does not seem to be related to that incident.
Interestingly, a separate Artifactory bug–CVE-2026-66384–was added to the KEV on Aug. 27. That flaw is a medium risk and requires authentication for exploitation. CISA added CVE-2026-82329 to the KEV on Sept. 2.
“JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions,” the advisory says.
September 2, 2026 | 2 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.