CISA added CVE-2026-82329, a CVSS 9.8 improper authentication flaw in JFrog Artifactory that hands unauthenticated network attackers administrative privileges under default configuration, to the Known Exploited Vulnerabilities catalog on September 2, 2026, with a three-day remediation deadline.
What Is It
JFrog Artifactory contains an authentication weakness (CWE-287) that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and full compromise of confidentiality, integrity, and availability.
Why It Matters
CISA's KEV listing confirms active exploitation. The accompanying SSVC assessment scores the vulnerability as exploitation: active, automatable: yes, and technicalImpact: total, meaning attacks can be reliably scripted at scale and yield complete control of the affected instance. Known ransomware campaign use is currently listed as Unknown. The KEV entry flags this CVE as requiring forensic triage, which indicates responders should assume potential compromise rather than simply patching and moving on.
What's Vulnerable
Self-managed JFrog Artifactory across six release branches. Affected version ranges (fixed version listed as the upper bound):
| Branch | Affected | Fixed in |
|---|---|---|
| Pre-7.111 | < 7.111.21 (CPE match from 7.111.4) | 7.111.21 |
| 7.117.x | 7.117.0 – < 7.117.28 | 7.117.28 |
| 7.125.x | 7.125.0 – < 7.125.20 | 7.125.20 |
| 7.133.x | 7.133.0 – < 7.133.29 | 7.133.29 |
| 7.146.x | 7.146.0 – < 7.146.38 | 7.146.38 |
| 7.161.x | 7.161.0 – < 7.161.20 | 7.161.20 |
Patch Status
Fixed builds are available for every affected branch. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. Due date: September 5, 2026.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329
- NVD, CVE-2026-82329, https://nvd.nist.gov/vuln/detail/CVE-2026-82329
- JFrog Security Advisories; https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- JFrog Artifactory Self-Managed Releases; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements), https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk