CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of a vulnerability impacting JFrog Artifactory, tracked as CVE-2026-82329. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.

JFrog Artifactory is a universal artifact repository manager — a central store for the binary outputs and dependencies of the software development lifecycle. It sits at the core of JFrog’s platform and acts as the single source of truth for build artifacts across an organization.

Vulnerability Details

The vulnerability has a critical severity rating with a CVSS v3.1 score of 9.8 out of 10. The vulnerability exists in Artifactory’s authentication handling, which fails to properly restrict access under the default configuration. Under the default configuration, the improper authentication vulnerability may allow an unauthenticated attacker with network access to obtain administrative privileges.

Active Exploitation

WatchTowr’s global Attacker Eye honeypot network data shows attackers minting administrator tokens and enumerating users, groups, credential sets, and federated access topologies. Some attempts appeared to stop after simply verifying that exploitation worked. Others proceeded to enumerate the environment. In a limited number of attacks, threat actors went further and created backdoor users, establishing an additional path for persistent administrative access.

Affected Versions

The vulnerability affects the following JFrog Artifactory versions:

  • from 7.111.4 before 7.111.21
  • from 7.117.0 before 7.117.28
  • from 7.125.0 before 7.125.20
  • from 7.133.0 before 7.133.29
  • from 7.146.0 before 7.146.38
  • from 7.161.0 before 7.161.20

Mitigation

Users must upgrade to the JFrog Artifactory version 7.161.20 to patch the vulnerability.

For more information, please refer to the JFrog Security Advisory.

Qualys Detection

Qualys customers can scan their devices with QID 735249 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://docs.jfrog.com/releases/docs/jfrog-security-advisories