Default-configuration authentication bypass grants administrative access in JFrog Artifactory (CVE-2026-82329)
SecurityWeek reported today that exploitation of this authentication bypass began just days after its August 28 disclosure, so teams that delay patching risk an unauthenticated attacker gaining full administrative control of their artifact repository and poisoning their software supply chain.
An authentication weakness in Artifactory under default configuration allows an unauthenticated attacker with network access to obtain administrative privileges. Administrative control over an artifact repository lets an attacker tamper with or replace hosted packages, making this a direct software supply-chain risk.
Affected: JFrog Artifactory < 7.111.21; JFrog Artifactory 7.117.0 – 7.117.27; JFrog Artifactory 7.125.0 – 7.125.19; JFrog Artifactory 7.133.0 – 7.133.28; JFrog Artifactory 7.146.0 – 7.146.36 (fixed in 7.146.38); JFrog Artifactory 7.161.0 – 7.161.19
How to Test
Confirm your self-managed Artifactory version against the affected ranges (below 7.111.21, or the 7.117, 7.125, 7.133, 7.146, and 7.161 lines before their fixed builds). Audit for unexpected administrative accounts, new access tokens, permission changes, and recently modified or uploaded artifacts, and review access logs for unauthenticated requests that resulted in privileged actions.
How to Patch
Upgrade to the fixed release for your line — 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 or later — per JFrog's security advisory. Until upgraded, restrict network access to the Artifactory instance so it is not reachable from untrusted networks.