NPM · SEPTEMBER 2026 · CONFIRMED

JFrog Artifactory Authentication Bypass: Critical Vulnerability CVE-2026-82329

Severity
CRITICAL
Affected component
jfrog artifactory (npm)
Patched version
Not yet available
CVE-2026-82329

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to create tokens that grant administrative access.

What happened

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. The flaw is present in the default configuration of self-managed instances of JFrog Artifactory, a repository manager used to store, organize, secure, and distribute software packages. An unauthenticated attacker with network access could exploit it to gain administrative permissions. Researchers at offensive security company watchTowr observed the flaw being exploited by attackers minting themselves admin tokens. Details about the flaw are scarce, and JFrog's advisory does not share many details beyond that the flaw is exploitable in Artifactory's default configuration.

To assess your exposure, check if you are using a self-managed instance of JFrog Artifactory with the default configuration. If so, you are potentially vulnerable. It is recommended to review your instance's configuration and apply any available patches or updates immediately.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using a self-managed instance of JFrog Artifactory with the default configuration, you are potentially affected.

What should I do right now?

Pin to a non-vulnerable version of JFrog Artifactory, upgrade to a patched version as soon as it becomes available, and rotate any administrative tokens in affected environments.

Has this been exploited in the wild?

Yes, this vulnerability is being actively exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats