JFrog Artifactory Auth Bypass CVE-2026-82329 Added to CISA Exploited List
JFrog confirmed an authentication bypass vulnerability, CVE-2026-82329, affecting self-hosted Artifactory deployments. The flaw stems from a default empty join key — the shared secret used for cluster node authentication — which allows attackers to forge administrative tokens without valid credentials. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2 September 2026, setting a remediation deadline of 5 September for federal agencies. Exploitation can lead to theft of private packages, injection of malicious builds into internal repositories, and compromise of stored credentials used by CI/CD pipelines. JFrog recommends upgrading to a patched release, setting a unique join key, rotating any exposed credentials, and reviewing access logs for suspicious token-based API activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in