CISA adds JFrog Artifactory auth bypass to exploited vulnerabilities list
CISA added CVE-2026-82329 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog: an authentication bypass in self-hosted JFrog Artifactory grants admin access without credentials. Chained with CVE-2026-42018 and CVE-2026-42016, it enables full instance takeover and supply chain poisoning.
- CVE-2026-82329: CVSS 9.8 auth bypass in self-hosted Artifactory
- Empty join key yields a predictable 32-byte token signing key
- Chain with CVE-2026-42018 and CVE-2026-42016 reaches admin control
- Fix: versions 7.161.20 and 7.133.11+, plus token and key rotation
Read next
Security