>samit_hota
Back to advisories

Security Advisory · SH-2026-164

CRITICALCVE-2026-82329CVSS 9.8OPEN

Critical JFrog Artifactory Vulnerability Grants Unauthenticated Admin Access

Affected: JFrog Artifactory

Samit Hota·
#kev#jfrog

A critical improper authentication vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, allows unauthenticated remote attackers to gain full administrative control over exposed instances under default configurations. Carrying a maximum CVSS v3.1 score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), this vulnerability requires no existing privileges or user interaction to execute. Any network-accessible instance running a vulnerable default setup is exposed to immediate takeover.

JFrog Artifactory Vulnerability Mechanics

The flaw stems from an improper authentication handling weakness (CWE-287) in Artifactory’s access control layer. When running under out-of-the-box configuration settings, the application fails to properly validate incoming authentication tokens or session parameters across specific API endpoints. An unauthenticated attacker capable of sending network requests to the instance can exploit this failure to elevate their security context directly to system administrator.

While current exploitation metrics reflect a 1.2% probability of active exploitation in the next 30 days (placing it in the 67th percentile among measured vulnerabilities), CVSS ratings reflect a catastrophic worst-case impact. The low attack complexity coupled with zero privilege requirements means automated scanners can easily discover and exploit exposed web interfaces or internal management ports.

Supply Chain Impact: Why Artifactory Targets Matter

Artifact repositories sit at the epicenter of modern CI/CD pipelines. An unauthenticated administrative compromise of Artifactory does not simply compromise a single application server; it compromises the entire software supply chain. An attacker who gains administrative privileges on an Artifactory node can:

  • Poison Software Builds: Swap legitimate compiled binaries, Docker images, Helm charts, or npm/PyPI packages with malicious variants that propagate downstream into production environments.
  • Exfiltrate Intellectual Property and Secrets: Extract proprietary source code artifacts, embedded API keys, database credentials, and service tokens stored within repository metadata.
  • Manipulate Access Controls: Generate persistent administrative API keys, modify user permissions, or alter identity provider integrations to maintain silent access across build infrastructure.

Organizations relying on Artifactory to serve internal microservices or push artifacts to customer-facing environments face severe downstream compromise if an unauthenticated attacker achieves administrative access.

Affected Versions and Remediation Path

Organizations running self-hosted or cloud-managed Artifactory instances must verify their release train and update immediately to the appropriate patched minor release provided by JFrog:

  • 7.111.x release stream: Upgrade versions 7.111.4 through 7.111.20 to 7.111.21 or later.
  • 7.117.x release stream: Upgrade versions 7.117.0 through 7.117.27 to 7.117.28 or later.
  • 7.125.x release stream: Upgrade versions 7.125.0 through 7.125.19 to 7.125.20 or later.
  • 7.133.x release stream: Upgrade versions 7.133.0 through 7.133.28 to 7.133.29 or later.
  • 7.146.x release stream: Upgrade versions 7.146.0 through 7.146.37 to 7.146.38 or later.
  • 7.161.x release stream: Upgrade versions 7.161.0 through 7.161.19 to 7.161.20 or later.

Before applying patches on internet-facing instances, security teams should conduct a forensic triage. Review system access logs, administrative user creation events, and audit logs for unexpected account provisioning or altered package checksums. Federal agencies and organizations adhering to CISA BOD 26-04 guidelines must enforce these remediations or isolate vulnerable instances prior to mandatory compliance deadlines.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call