A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited to mint administrative tokens on self-managed instances. Because Artifactory artifacts are trusted by downstream build and deployment systems, attackers could poison packages and potentially trigger malicious code execution across connected environments. #CVE-2026-82329 #JFrogArtifactory #watchTowr #GuillermoRauch
Keypoints
- CVE-2026-82329 enables authentication bypass in default Artifactory deployments.
- Attackers can create admin tokens without authentication.
- watchTowr observed active exploitation in the wild.
- Compromised access can expose users, groups, artifacts, and security settings.
- JFrog released fixes in multiple Artifactory versions on August 28.