A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access.

Exploitation of the JFrog Artifactory authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Attackers exploit a JFrog Artifactory authentication bypass to mint admin tokens and enumerate users on default configurations.