CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329)
CISA added the actively exploited JFrog Artifactory flaw CVE-2026-82329 (CVSS 9.8) to its KEV catalog; unauthenticated attackers gain admin access.
CISA added CVE-2026-82329, a critical improper authentication flaw in JFrog Artifactory, to its Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. The CVSS v3.1 9.8 flaw allows unauthenticated attackers with network access to obtain administrative privileges under the default configuration. WatchTowr honeypot data shows attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and in some cases creating backdoor users for persistence. Users must upgrade to Artifactory 7.161.20 or the applicable fixed release; Qualys detects vulnerable assets via QID 735249.
- CISA KEV addition sets a federal patching deadline of September 5, 2026
- CVSS 9.8 improper authentication flaw grants admin rights under default configuration
- WatchTowr observed token minting, environment enumeration, and backdoor user creation
- Fixed versions include 7.161.20; multiple 7.x release branches affected
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82329 | Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018. Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product. | 9.8 | 8% | KEV PoC ×2 |
| largetens of thousands of deployments, many of them internet-exposed (estimate) |
Full article300 words · extracted from threatprotect.qualys.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of a vulnerability impacting JFrog Artifactory, tracked as CVE-2026-82329. CISA added the vulnerability to itsKnown Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
JFrog Artifactory is a universal artifact repository manager — a central store for the binary outputs and dependencies of the software development lifecycle. It sits at the core of JFrog’s platform and acts as the single source of truth for build artifacts across an organization.
Vulnerability Details
The vulnerability has a critical severity rating with a CVSS v3.1 score of 9.8 out of 10. The vulnerability exists in Artifactory’s authentication handling, which fails to properly restrict access under the default configuration. Under the default configuration, the improper authentication vulnerability may allow an unauthenticated attacker with network access to obtain administrative privileges.
Active Exploitation
WatchTowr’s global Attacker Eye honeypot network data shows attackers minting administrator tokens and enumerating users, groups, credential sets, and federated access topologies. Some attempts appeared to stop after simply verifying that exploitation worked. Others proceeded to enumerate the environment. In a limited number of attacks, threat actors went further and created backdoor users, establishing an additional path for persistent administrative access.
Affected Versions
The vulnerability affects the following JFrog Artifactory versions:
- from 7.111.4 before 7.111.21
- from 7.117.0 before 7.117.28
- from 7.125.0 before 7.125.20
- from 7.133.0 before 7.133.29
- from 7.146.0 before 7.146.38
- from 7.161.0 before 7.161.20
Mitigation
Users must upgrade to the JFrog Artifactory version 7.161.20 to patch the vulnerability.
For more information, please refer to the JFrog Security Advisory.
Qualys Detection
Qualys customers can scan their devices with QID 735249 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Text extracted automatically; images, tables and formatting may be missing. Original: https://threatprotect.qualys.com/2026/09/03/cisa-added-jfrog-artifactory-vulnerability-to-its-known-exploited-vulnerabilities-catalog-cve-2026-82329/