Artifactory Bypass Is Hitting Self-Hosted Instances

WatchTowr says attackers are already exploiting CVE-2026-82329 in JFrog Artifactory just days after disclosure, and the issue can hand an unauthenticated network attacker administrative privileges. JFrog says cloud instances have already been patched, leaving the immediate exposure on self-hosted deployments that have not moved to a fixed version. The flaw is an authentication bypass: a request that should fail the login check can land with admin rights instead. In practice, that means an attacker can mint admin tokens and act like a legitimate repository operator, which matters because Artifactory often sits in front of artifacts, packages, containers, and models that build systems trust. For teams running their own Artifactory, the risk is not just a broken login wall. A compromised repository server can become a foothold in the software supply chain it serves, and anything downstream that pulls from it inherits that trust until the instance is fixed and the admin path is no longer open.

Part of the PlainSec briefing for 2026-09-01

Editions

Sources