Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4038 articles · 206785 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-82329KEVEXPLOITEDPATCHED
jfrog · artifactory

Potential authentication bypass leading to administrative access in Artifactory

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Affected Products

VendorProductVersions
jfrogartifactory0, 7.117.0, 7.125.0, 7.133.0, 7.146.0, 7.161.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jfrogartifactorycert_advisory90%

References

  • https://docs.jfrog.com/releases/docs/jfrog-security-advisories(vendor-advisory)
  • https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases(vendor-advisory)

Related News (5 articles)

Tier D
SecurityWeek6h ago
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
→ No new info (linked only)
Tier B
CERT-FR16h ago
Multiples vulnérabilités dans JFrog Artifactory (01 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[NEU] [hoch] JFrog Artifactory: Schwachstelle ermöglicht Erlangen von Administratorrechten
→ No new info (linked only)
Tier E
Hacker News1d ago
Critical CVE: JFrog Artifactory Authentication Bypass
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-82329 | JFrog Artifactory up to 7.161.19 privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.111.217.117.287.125.207.133.297.146.387.161.20
CWECWE-287
PublishedAug 28, 2026
Last enriched3d ago
Trending Score133🔥
Source articles5
Independent5
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-66384EXPKEV
Authenticated users may write data outside the intended Docker cache path
Trending: 101
HIGHCVE-2026-70551
Server-Side Request Forgery Via VCS remote download in JFrog Artifactory
Trending: 40
HIGHCVE-2026-69104
Potential unauthorized repository migration in JFrog Artifactory
Trending: 40
MEDIUMCVE-2026-70550
Potential unauthorized access to private Composer repository metadata in JFrog Artifactory
Trending: 36
LOWCVE-2026-70548
SSRF In CocoaPods Via JFrog Artifactory External Dependency
Trending: 34

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Aug 28, 2026
Added to CISA KEV
Aug 28, 2026
Discovered by ZDM
Aug 28, 2026
Actively Exploited
Aug 31, 2026
Patch Available
Aug 31, 2026