Vulnerabilities · 6h ago

Artifactory Login Bypass Hits Supply-Chain Trust

CSIRT-ITA said it found active exploitation of CVE-2026-82329 in JFrog Artifactory, the repository manager that many build and release pipelines use as a software supply-chain control point. The affected branches include several 7.x lines, with fixed builds starting at 7.133.29.

The flaw is an authentication bypass: a remote unauthenticated attacker can send crafted HTTPS requests, slip past the login gate, and reach administrator privileges on systems left at default settings. In plain terms, the attacker is not just inside one account; they can act as the repository admin, which means they can alter the artifacts downstream builds trust.

That makes the exposure bigger than the product itself. If Artifactory sits between developers and the packages they ship, a compromise can poison builds and releases even after the server is patched, because the trust boundary it mediates is what got crossed.

CVE-2026-82329

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: jFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated… EPSS 14% (96th percentile).

CISA federal remediation date Sep 5 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories