CVE Research
sekurity-team
InSEKurity of the Week (CW36/2026): JFrog Artifactory Authentication Bypass to Admin (CVE-2026-82329)
A default-configuration authentication weakness in JFrog Artifactory lets an unauthenticated attacker mint administrator tokens. Patched on August 28, exploited in the wild by September 1, in CISA KEV by September 2 -- and the box it compromises is the one your entire build pipeline trusts.
Exploit
01
