• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-82329: pre-auth privilege escalation in JFrog Artifactory

Unauthenticated remote attackers can obtain administrative privileges on JFrog Artifactory, CVE-2026-82329, against default configurations. Affected releases include 7.x versions before 7.111.21 and several later 7.x ranges fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20; an attacker only needs network access and no valid credentials under default settings to exploit the flaw.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.14121
CWE
CWE-287
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth administrative takeover added to CISA’s KEV with a short federal remediation deadline, and public exploit code exists — prioritize patching exposed Artifactory instances immediately.

What is CVE-2026-82329?

Unauthenticated remote attackers can obtain administrative privileges on JFrog Artifactory, CVE-2026-82329, against default configurations. Affected releases include 7.x versions before 7.111.21 and several later 7.x ranges fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20; an attacker only needs network access and no valid credentials under default settings to exploit the flaw. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of JFrog Artifactory are affected?

BRANCHAFFECTEDFIXED
7.xbefore 7.111.217.111.21
7.x7.117.0 – before 7.117.287.117.28
7.x7.125.0 – before 7.125.207.125.20
7.x7.133.0 – before 7.133.297.133.29
7.x7.146.0 – before 7.146.387.146.38
7.x7.161.0 – before 7.161.207.161.20

Is CVE-2026-82329 being exploited?

CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on 2026-09-02; US federal agencies were required to mitigate it by 2026-09-05. Public exploit code is available.

How to fix CVE-2026-82329

  1. Upgrade Artifactory to a fixed release: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 or 7.161.20 as applicable.
  2. If you cannot immediately upgrade, restrict network exposure of Artifactory to trusted hosts and disable any internet-facing access.
  3. Follow vendor guidance and apply recommended mitigations from JFrog for this CVE.
  4. Monitor Artifactory logs and audit for administrative account creation or suspicious activity and rotate credentials and API keys where possible.

Frequently asked questions

Is CVE-2026-82329 being actively exploited?

CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on 2026-09-02 and required mitigation by 2026-09-05; public exploit code is available.

Which Artifactory versions are affected by CVE-2026-82329?

Affected Artifactory 7.x releases include versions before 7.111.21 and the ranges 7.117.0–before 7.117.28, 7.125.0–before 7.125.20, 7.133.0–before 7.133.29, 7.146.0–before 7.146.38, and 7.161.0–before 7.161.20.

Is there a patch for CVE-2026-82329?

Yes. Patches are available; fixed releases include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20.

Does CVE-2026-82329 require authentication?

No. The vulnerability is an authentication weakness that can allow an unauthenticated attacker with network access to obtain administrative privileges under default configuration.

References