Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory
JFrog disclosed CVE-2026-82329 (CVSS 9.8) in self-hosted Artifactory: an empty default join key lets an unauthenticated attacker sign a join JWT and obtain an admin token. Exploitation in the wild was recorded on September 1, 2026; CISA added related vulnerabilities to its KEV catalog.
- CVE-2026-82329: authentication bypass in JFrog Access, CVSS 9.8
- Empty default join key yields a predictable 32-byte signing key
- In-the-wild attacks recorded September 1, three days after disclosure
- CISA added vulnerabilities to KEV, federal deadline September 25
Read next
Security