CVE-2026-70550

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 16:17

Updated : 2026-08-28 21:29


NVD link : CVE-2026-70550

Mitre link : CVE-2026-70550

CVE.ORG link : CVE-2026-70550


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization