OpenInfra Europe, the regional hub of the OpenInfra Foundation, has warned that its self-hosted JFrog Artifactory instance was breached. The security notice posted on its homepage urges anyone who downloaded or installed artifacts from artifactory.nordix.org between August 28 and September 15, 2026 to stop using them immediately, remove them from pipelines, and treat them as potentially compromised.
The attackers gained access by exploiting CVE-2026-82329, an authentication bypass vulnerability that allowed unauthenticated intruders to obtain admin privileges. That vulnerability was publicly disclosed on August 28, added to CISA's Known Exploited Vulnerabilities catalog on September 2, and in-the-wild exploitation reportedly began on August 31. OpenInfra Europe says its instance was compromised that same day, but the breach was only discovered on September 15, after a legitimate user was denied access.
The affected system was isolated as soon as the breach was found, and an investigation is underway, but the full scope and impact have not yet been determined. OpenInfra Europe is part of the non-profit Linux Foundation and supports open source infrastructure projects, most notably OpenStack. JFrog Artifactory is a binary repository manager used to store and serve build outputs and dependencies, and organizations can self-host it or use it as a managed service.