← All Advisories

CVE-2026-82329: JFrog Artifactory Improper

Status: KEV  |  Advisory ID: CVE-2026-82329

Key Details

CVECVE-2026-82329
CVSSCVSS 9.8 (Critical).
Affected productsJFrog Artifactory
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-287 (Improper Authentication)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02.
Exploitation prediction (EPSS)8% probability of exploitation in the next 30 days (94% percentile) -- FIRST.org's EPSS model.

What to Know

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-82329
Vendor advisoryhttps://docs.jfrog.com/releases/docs/jfrog-security-advisories