OpenInfra Europe Artifactory Breach Threatens Downstream Builds
OpenInfra Europe says its self-hosted JFrog Artifactory at artifactory.nordix.org was breached through CVE-2026-82329, with artifacts served from Aug. 28 to Sept. 15 potentially compromised. The foundation says anyone who downloaded or installed packages in that window should stop using them.
The flaw is an authentication bypass: unauthenticated attackers could reach admin-level access, then alter the repository itself. That matters because Artifactory is a trusted package source, so tampered artifacts can flow into build pipelines, cached dependencies, and internal systems without looking like a separate malware download.
The breach was discovered on Sept. 15 after a legitimate user was denied access, and OpenInfra Europe says the full scope is still unknown. For any team that mirrors internal repositories or pulls from shared build infrastructure, the exposure is not confined to one server; it can persist wherever those artifacts were already consumed.