JFrog Artifactory CVE-2026-82329: The Default Join Key as an Authentication Bypass Why an artifact repository is a credential store with a UI An artifact repository holds the build outputs that everything else deploys, and it holds the credentials needed to pull them. JFrog confirmed an authentication bypass in self-hosted Artifactory, CVE-2026-82329, and CISA added it to the Known Exploited Vulnerabilities catalog on 2 September 2026, with a remediation deadline of 5 September ...