JFrog Artifactory Authentication Bypass: Critical Vulnerability CVE-2026-82329
- Severity
- CRITICAL
- Affected component
- jfrog artifactory (npm)
- Patched version
- Not yet available
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to create tokens that grant administrative access.
What happened
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. The flaw is present in the default configuration of self-managed instances of JFrog Artifactory, a repository manager used to store, organize, secure, and distribute software packages. An unauthenticated attacker with network access could exploit it to gain administrative permissions. Researchers at offensive security company watchTowr observed the flaw being exploited by attackers minting themselves admin tokens. Details about the flaw are scarce, and JFrog's advisory does not share many details beyond that the flaw is exploitable in Artifactory's default configuration.
To assess your exposure, check if you are using a self-managed instance of JFrog Artifactory with the default configuration. If so, you are potentially vulnerable. It is recommended to review your instance's configuration and apply any available patches or updates immediately.
What to do about it
- Pin to a non-vulnerable version of JFrog Artifactory.
- Upgrade to a patched version of JFrog Artifactory as soon as it becomes available.
- Rotate any administrative tokens in affected environments.
- Monitor the primary sources for updates on the vulnerability and any available patches.
How 0Day would have caught this
jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using a self-managed instance of JFrog Artifactory with the default configuration, you are potentially affected.
What should I do right now?
Pin to a non-vulnerable version of JFrog Artifactory, upgrade to a patched version as soon as it becomes available, and rotate any administrative tokens in affected environments.
Has this been exploited in the wild?
Yes, this vulnerability is being actively exploited in the wild.