An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 16:17
Updated : 2026-08-28 21:29
NVD link : CVE-2026-70550
Mitre link : CVE-2026-70550
CVE.ORG link : CVE-2026-70550
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
