A critical authentication bypass vulnerability, tracked as CVE-2026-82329, in self-hosted instances of JFrog Artifactory is under active exploitation. The flaw allows an unauthenticated attacker with network access to the Artifactory instance to gain full administrative privileges. Given Artifactory's central role in the software development lifecycle (SDLC) and CI/CD pipelines, this vulnerability poses a severe risk to the software supply chain. Attackers have been observed exploiting this flaw in the wild to create unauthorized administrator tokens. JFrog has released patches, and immediate action is required by all organizations running self-hosted Artifactory deployments.
The vulnerability, CVE-2026-82329, is an authentication bypass that affects default configurations of JFrog Artifactory. An unauthenticated attacker can exploit this flaw to escalate their privileges to that of an administrator. The rapid weaponization of this vulnerability, with exploitation observed just days after disclosure, underscores the high-risk nature of the flaw. A successful exploit grants the attacker complete control over the Artifactory instance, including the ability to access, modify, or poison software artifacts, steal proprietary source code, and disrupt development and deployment pipelines.
Security firm WatchTowr reported on September 1, 2026, that it has observed active in-the-wild exploitation of CVE-2026-82329. Attackers are reportedly using the vulnerability to "mint themselves admin tokens," effectively creating persistent administrative access to compromised servers. This indicates that threat actors are not only aware of the vulnerability but have developed reliable exploits and are actively using them to compromise targets.
Another vulnerability, CVE-2026-66384, was previously added to the CISA Known Exploited Vulnerabilities (KEV) catalog, but CVE-2026-82329 has not yet been added at the time of this report.
Compromise of a JFrog Artifactory instance can have catastrophic consequences for an organization's software supply chain. An attacker with administrative access can:
The impact is particularly severe for industrial and manufacturing organizations that rely on self-hosted repositories for managing software for operational technology (OT) and connected devices.
The following patterns could indicate related activity:
Security teams should immediately implement the following detection and response measures:
artifactory-access.log) and request logs (artifactory-request.log) in a SIEM. Create alerts for the creation of new administrative users or access tokens, especially from unauthenticated contexts or unusual IP addresses. This aligns with D3FEND's User Account Monitoring (D3-UAM).Immediately apply the patches provided by JFrog to remediate the vulnerability.
Restrict network access to the Artifactory instance, ensuring it is not exposed to the internet and is only accessible from trusted internal sources.
Regularly audit Artifactory logs for signs of compromise, such as unusual administrative account or token creation.
Implement the principle of least privilege for all user and service accounts interacting with Artifactory.
JFrog releases patches for the authentication bypass vulnerability.
WatchTowr reports observing active in-the-wild exploitation of CVE-2026-82329.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.