CVE-2026-82329 is a CVSS 9.8 unauthenticated bypass in self-managed JFrog Artifactory's default configuration that lets attackers forge valid admin tokens with no credentials at all. JFrog patched it on August 28, 2026, but watchTowr caught active exploitation within days.
Read the full story: Critical JFrog Artifactory Bug Lets Hackers Forge Admin Tokens →
Transcript
JFrog Artifactory just had one of the worst kinds of bugs. An unauthenticated attacker could forge a valid administrator token, no credentials, no login, nothing. That's CVE-2026-82329, a 9.8 out of 10 on the severity scale. JFrog shipped the fix on August 28th, in version 7.161.20. But here's the problem. Security researchers at watchTowr caught attackers actively exploiting it within days of disclosure. Because Artifactory stores a company's build artifacts and packages, a forged admin account isn't just account takeover, it's a door into the software supply chain. If you're running self-managed Artifactory, the fix is simple: patch immediately, rotate every token you've issued, and check for admin accounts nobody remembers creating.