Skip to content
JFrogCVE-2026-82329

JFrog artifactory: improper authentication

Critical9.8CVE-2026-82329 · Published Aug 28, 2026 · updated Sep 3, 2026

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
< 7.111.217.111.21
>= 7.117.0, < 7.117.287.117.28
>= 7.125.0, < 7.125.207.125.20
>= 7.133.0, < 7.133.297.133.29
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: server-side request forgery
Low3.5Aug 25
JFrog artifactory: missing authorization
Medium6.5Aug 25
JFrog artifactory: server-side request forgery
High8.5Aug 25
JFrog artifactory: information disclosure
High7.6Aug 25
JFrog artifactory: improper input validation
High8.8Aug 12
JFrog artifactory: improper authentication
High7.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.