{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-82329",
  "revision": 1,
  "title": "JFrog Artifactory — Improper Authentication to Unauthenticated Admin Access",
  "summary": "An authentication weakness in JFrog Artifactory, present under the default configuration, lets an attacker with only network access to the service bypass login and gain full administrative control of the instance.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.07666,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-09-02",
    "prerequisites": "Network access to an Artifactory instance running its default configuration"
  },
  "mitre_attack": [
    "T1190",
    "T1078"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply JFrog's advisory mitigations to Artifactory, restrict network access to the instance until then, and audit admin accounts and tokens for unauthorized changes.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-82329",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
    },
    {
      "type": "writeup",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329"
    }
  ],
  "published_at": "2026-08-28T20:20:21.293Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "jfrog-artifactory",
    "artifact-repository",
    "improper-authentication",
    "authentication-bypass"
  ]
}
