JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability
Info Listed in CISA KEV
Summary
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- JFrog:Artifactory
Sources
- CISA KEV DATABASE
Original Links
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories reference
- https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
- https://nvd.nist.gov/vuln/detail/CVE-2026-82329 reference
Timeline
- kev_ingest CISA KEV