DIRAS TAKE
Urgent: this is a pre-auth administrative takeover added to CISA’s KEV with a short federal remediation deadline, and public exploit code exists — prioritize patching exposed Artifactory instances immediately.
What is CVE-2026-82329?
Unauthenticated remote attackers can obtain administrative privileges on JFrog Artifactory, CVE-2026-82329, against default configurations. Affected releases include 7.x versions before 7.111.21 and several later 7.x ranges fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20; an attacker only needs network access and no valid credentials under default settings to exploit the flaw. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of JFrog Artifactory are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | before 7.111.21 | 7.111.21 |
| 7.x | 7.117.0 – before 7.117.28 | 7.117.28 |
| 7.x | 7.125.0 – before 7.125.20 | 7.125.20 |
| 7.x | 7.133.0 – before 7.133.29 | 7.133.29 |
| 7.x | 7.146.0 – before 7.146.38 | 7.146.38 |
| 7.x | 7.161.0 – before 7.161.20 | 7.161.20 |
Is CVE-2026-82329 being exploited?
CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on 2026-09-02; US federal agencies were required to mitigate it by 2026-09-05. Public exploit code is available.
How to fix CVE-2026-82329
- Upgrade Artifactory to a fixed release: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 or 7.161.20 as applicable.
- If you cannot immediately upgrade, restrict network exposure of Artifactory to trusted hosts and disable any internet-facing access.
- Follow vendor guidance and apply recommended mitigations from JFrog for this CVE.
- Monitor Artifactory logs and audit for administrative account creation or suspicious activity and rotate credentials and API keys where possible.
Frequently asked questions
Is CVE-2026-82329 being actively exploited?
CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on 2026-09-02 and required mitigation by 2026-09-05; public exploit code is available.
Which Artifactory versions are affected by CVE-2026-82329?
Affected Artifactory 7.x releases include versions before 7.111.21 and the ranges 7.117.0–before 7.117.28, 7.125.0–before 7.125.20, 7.133.0–before 7.133.29, 7.146.0–before 7.146.38, and 7.161.0–before 7.161.20.
Is there a patch for CVE-2026-82329?
Yes. Patches are available; fixed releases include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20.
Does CVE-2026-82329 require authentication?
No. The vulnerability is an authentication weakness that can allow an unauthenticated attacker with network access to obtain administrative privileges under default configuration.
References
- nvd.nist.gov/vuln/detail/CVE-2026-82329
- cve.org/CVERecord?id=CVE-2026-82329
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329
- docs.jfrog.com/releases/docs/jfrog-security-advisories
- docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- All JFrog CVEs on CVE Radar
- CVEs published in September 2026