JFrog Artifactory Auth Bypass Turns Fortune 100 CI/CD Pipelines Into Supply Chain Attack Surface
On August 28, 2026, JFrog disclosed CVE-2026-82329, an improper authentication vulnerability affecting self-hosted instances of JFrog Artifactory. With a CVSS score of 9.8, the flaw allows an unauthenticated attacker with network access to bypass authentication and obtain administrative privileges. The vector is straightforward: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Because Artifactory serves as the central artifact repository for 83% of…