← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 1, 2026 · 13:06via Cyber Security News

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

Brief

A critical authentication bypass vulnerability in JFrog Artifactory , tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges.

WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin tokens.” An attacker with a valid administrator token could control the affected Artifactory environment, including repositories, user accounts, access permissions, build artifacts, and software packages stored in the platform.

JFrog disclosed the vulnerability on August 28, 2026, and classified it as critical. The company described CVE-2026-82329 as an improper authentication issue, tracked under CWE-287.

Under the default configuration, a remote attacker does not need valid credentials to exploit the weakness and may obtain administrative privileges.

Read more on Cyber Security News