CVE Tools

CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key

Bishop FoxBy Nate Robb9 min read

Reported exploitedJFrog Artifactory

Our summary

Bishop Fox has detailed active in-the-wild exploitation of CVE-2026-82329, a critical authentication bypass in self-managed JFrog Artifactory that allows attackers to obtain unauthenticated administrator access. The vulnerability stems from an empty cluster join key on default configurations, enabling the generation of permanent admin-scoped tokens. Affected users should immediately update to version 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 to mitigate this risk.

Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR
  • JFrog Artifactory is one of the most widely deployed systems for storing and distributing the software packages companies build and depend on. A flaw in how it verified membership of its own server cluster meant that anyone who could reach an internet-facing instance could simply ask for administrator access, and the server would grant it. Attackers began exploiting it within days of the flaw being disclosed. An Artifactory administrator can read every package an organization ships, upload malicious ones that downstream builds install as trusted, and retrieve credentials that reach the systems around it, so the damage does not stop at Artifactory.
  • CVE-2026-82329 is a critical unauthenticated authentication bypass in self-managed JFrog Artifactory, rated CVSS 9.8. On a default install, JFrog Access registers a cluster join key whose id and signing secret are both derivable by anyone, so one forged join request to an endpoint that requires no authentication returns an admin-scoped token. Bishop Fox reproduced the full chain to Artifactory administrator against a default 7.111.20 instance and confirmed the fix on 7.111.21. Patch to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20. The CVE is KEV-listed with in-the-wild exploitation reported, and JFrog published no discovery credit.
…
Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store