Intel

AIKIDO-2026-853477

jfrog-artifactory-oss is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-82329 Published Yesterday

98

Critical Risk

This Affects:

OSjfrog-artifactory-oss
7.111.4 - 7.111.20
Fixed in 7.111.21
7.117.0 - 7.117.27
Fixed in 7.117.28
7.125.0 - 7.125.19
Fixed in 7.125.20
7.133.0 - 7.133.28
Fixed in 7.133.29
7.146.0 - 7.146.36
Fixed in 7.146.38
7.161.0 - 7.161.19
Fixed in 7.161.20
Are you affected? Scan for Free

TL;DR

JFrog Artifactory has an authentication weakness that, under the default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. A successful exploit yields full administrative control of the Artifactory instance, and therefore of the artifacts, container images, and packages it serves to downstream builds. This issue is reported to be exploited in the wild within days of disclosure, with attackers minting themselves administrative tokens. JFrog has released patched builds on the supported 7.111, 7.117, 7.125, 7.133, 7.146, and 7.161 branches; after upgrading, review administrator accounts and issued access tokens, revoke anything unrecognized, and treat artifacts published while exposed as suspect.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run a self-hosted JFrog Artifactory instance. All self-hosted instances prior to the versions patched on 28 August 2026 are affected, and under the default configuration the issue is reachable without any credentials. Cloud-hosted Artifactory instances have already been patched by JFrog and are not vulnerable.

Background info

jfrog-artifactory-oss is vulnerable to Authentication Bypass in versions 7.111.4 - 7.111.20, 7.117.0 - 7.117.27, 7.125.0 - 7.125.19, 7.133.0 - 7.133.28, 7.146.0 - 7.146.36 and 7.161.0 - 7.161.19.

How to fix this

Upgrade the jfrog-artifactory-pro and/or the jfrog-artifactory-oss library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform