JFrog Artifactory vulnerability discovered with downstream effects CVE-2026-82329

CVSSv3: 9.8

JFrog has an authentication failure in the Artifactory component that allows for unrestricted administrative access to the underlying host.

The Artifactory is a binary repository manager - certainly not the kind of thing that you want to have authentication problems. The exact flaw has not been released yet. However, Artifactory is used by 527 open source projects of various levels of popularity. It is worth making sure your dependency scanning is up to date (you are running dependency scanning right?) and review your use of Artifactory.

https://www.cve.org/CVERecord?id=CVE-2026-82329

This is the second major access control issue in the Artifactory in the last month (CVE-2026-66014).

WatchTowr reports this is already exploited in the wild.

https://x.com/watchtowrcyber/status/2094639075726668267

Notes

Yes, this is the vulnerability that led directly to the OpenAI/HuggingFace incident.

https://x.com/rauchg/status/2094122005193003077

2 Likes