Status: KEV
| Advisory ID: CVE-2026-82329
Key Details
| CVE | CVE-2026-82329 |
| Vulnerability Name | JFrog Artifactory Improper Authentication Vulnerability |
| CVSS Score / Version | 9.8 (Critical) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | JFrog Artifactory |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-287 (Improper Authentication) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02. |
| Exploitation prediction (EPSS) | 14.12% probability of exploitation in the next 30 days (96% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
What to Do
Monitor JFrog's web page for any future patch releases. See vendor advisory link below.
References
KEV Required Action