NPM · SEPTEMBER 2026 · CONFIRMED

JFrog Artifactory Authentication Bypass Vulnerability: Critical Threat

Severity
HIGH
Affected component
jfrog artifactory (npm)
Patched version
Not yet available
CVE-2026-82329

A critical authentication bypass vulnerability in the JFrog Artifactory npm package has been exploited in the wild. Users of JFrog Artifactory are advised to upgrade to the latest version and review access controls.

What happened

The JFrog Artifactory npm package contains a critical authentication bypass vulnerability tracked as CVE-2026-82329. This flaw allows unauthenticated attackers with network access to obtain administrative privileges under default configurations. Threat actors have begun exploiting this vulnerability to mint admin tokens, as reported by multiple independent sources. The vulnerability was patched by JFrog with Artifactory version 7.161.20 released on August 28, 2026.

The affected versions include 7.161.0 > 7.161.19, 7.146.0 > 7.146.36, 7.133.0 > 7.133.28, 7.125.0 > 7.125.19, 7.117.0 > 7.117.27, and 7.111.4 > 7.111.21. The issue resides in JFrog Access, which is designed to issue and validate credentials. Instances without an additional join key configured receive a 'phantom' join key that attackers can abuse to forge access and mint administrator-level credentials.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using JFrog Artifactory versions 7.161.0 > 7.161.19, 7.146.0 > 7.146.36, 7.133.0 > 7.133.28, 7.125.0 > 7.125.19, 7.117.0 > 7.117.27, or 7.111.4 > 7.111.21, you are affected.

What should I do right now?

Upgrade to the latest version of JFrog Artifactory and review your access controls.

Has this been exploited in the wild?

Yes, this vulnerability has been exploited in the wild by attackers to mint admin tokens.

Sources

Join the 0Day waitlist →

← Back to all threats