Description
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Published: 2026-08-28
Score: 9.8 Critical
EPSS: 7.7% Low
KEV: Yes
Impact: Administrative Access
Action: Immediate Patch
AI Analysis

Impact

JFrog Artifactory contains an authentication weakness that, when the system is left in its default state, may permit an unauthenticated attacker with network connectivity to gain administrative privileges. The flaw is a bypass of the authentication mechanism (CWE‑287). Once exploited, the attacker can perform any action that an administrator can, including modifying configuration, accessing sensitive artifacts, and potentially executing arbitrary code on the host. This can compromise the confidentiality, integrity, and availability of the Artifactory instance and any data stored within it.

Affected Systems

The vulnerability applies to JFrog Artifactory products when operating under the default configuration. The specific affected product is JFrog Artifactory; no particular version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, meaning the vulnerability has a wide impact scope and high exploitation potential. The EPSS score of 8% indicates a high likelihood of exploitation, and its inclusion in the CISA KEV catalog confirms that this authentication weakness has been observed in the wild. The likely attack vector is an unauthenticated network attacker reaching any endpoint exposed by Artifactory, bypassing authentication checks, and escalating privileges to administrative level. Such an exploit requires no privileged credentials and can be carried out remotely in the presence of network access to the Artifactory instance.

Generated by OpenCVE AI on September 3, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JFrog Artifactory to the latest patched release as documented by JFrog.
  • Disable anonymous access in the Artifactory configuration to prevent unauthenticated users from reaching any service.
  • Reconfigure Artifactory’s authentication settings so that all endpoints require verified credentials before granting access.

Generated by OpenCVE AI on September 3, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*

Wed, 02 Sep 2026 18:30:00 +0000


Wed, 02 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-09-02T00:00:00+00:00', 'dueDate': '2026-09-05T00:00:00+00:00'}


Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Title Potential authentication bypass leading to administrative access in Artifactory
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-09-03T03:56:03.621Z

Reserved: 2026-08-28T14:26:47.580Z

Link: CVE-2026-82329

cve-icon Vulnrichment

Updated: 2026-08-31T18:45:34.190Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T20:20:21.293

Modified: 2026-09-03T13:06:15.630

Link: CVE-2026-82329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:15:05Z

Weaknesses