JFrog Artifactory 7.111.4 < 7.111.21 / 7.117.x < 7.117.28 / 7.125.x < 7.125.20 / 7.133.x < 7.133.29 / 7.146.x < 7.146.38 / 7.161.x < 7.161.20 Authentication Bypass

critical Nessus Plugin ID 343483

Synopsis

An application installed on the remote host is affected by an authentication bypass vulnerability.

Description

According to its self-reported version number, the version of JFrog Artifactory installed on the remote host is 7.111.4 prior to 7.111.21, 7.117.x prior to 7.117.28, 7.125.x prior to 7.125.20, 7.133.x prior to 7.133.29, 7.146.x prior to 7.146.38, or 7.161.x prior to 7.161.20. It is, therefore, affected by an authentication bypass vulnerability.
Under default configuration, an unauthenticated attacker with network access may obtain administrative privileges.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to JFrog Artifactory version 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20, or later.

See Also

https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases

https://docs.jfrog.com/releases/docs/jfrog-security-advisories

Plugin Details

Severity: Critical

ID: 343483

File Name: jfrog_artifactory_improper_authentication_cve_2026_82329.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 9/7/2026

Updated: 9/7/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

Percentile: 99.76

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-82329

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:jfrog:artifactory

Required KB Items: installed_sw/Artifactory

Patch Publication Date: 8/28/2026

Vulnerability Publication Date: 8/28/2026

Reference Information

CVE: CVE-2026-82329

IAVA: 2026-A-0915