A critical vulnerability, CVE-2026-82329, has been discovered in JFrog's Artifactory software, allowing attackers to bypass authentication and gain administrative access without user interaction. Disclosed on August 28, the flaw has a CVSS score of 9.8 and poses significant risk as it allows attackers to control repositories, steal, or modify software packages. Exploit activity was reported shortly after the disclosure, with some attackers successfully minting admin tokens and enumerating user data.
JFrog has released patches, but affected organizations are advised to treat exposed systems as potentially compromised, audit logs, and rotate credentials. JFrog emphasized that this incident is unrelated to previous attacks involving OpenAI's agents.