Vulnerabilities (CVE)

Filtered by vendor Jfrog Subscribe
Filtered by product Artifactory
Total 70 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66014 1 Jfrog 1 Artifactory 2026-09-15 N/A 8.8 HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-42018 1 Jfrog 1 Artifactory 2026-09-12 N/A 7.5 HIGH
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-42016 1 Jfrog 1 Artifactory 2026-09-12 N/A 8.1 HIGH
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2026-66016 1 Jfrog 1 Artifactory 2026-09-11 N/A 6.7 MEDIUM
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-69105 1 Jfrog 1 Artifactory 2026-09-11 N/A 8.1 HIGH
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-69107 1 Jfrog 1 Artifactory 2026-09-11 N/A 5.9 MEDIUM
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-70547 1 Jfrog 1 Artifactory 2026-09-11 N/A 4.3 MEDIUM
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69106 1 Jfrog 1 Artifactory 2026-09-11 N/A 8.8 HIGH
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-82329 1 Jfrog 1 Artifactory 2026-09-03 N/A 9.8 CRITICAL
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVE-2026-66375 1 Jfrog 1 Artifactory 2026-09-02 N/A 8.1 HIGH
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVE-2026-66376 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.2 MEDIUM
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66377 1 Jfrog 1 Artifactory 2026-09-02 N/A 5.3 MEDIUM
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66378 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.3 MEDIUM
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66379 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.3 MEDIUM
An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66380 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.3 MEDIUM
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-66381 1 Jfrog 1 Artifactory 2026-09-02 N/A 5.3 MEDIUM
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVE-2026-66382 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.3 MEDIUM
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-68752 1 Jfrog 1 Artifactory 2026-09-02 N/A 7.2 HIGH
A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-68753 1 Jfrog 1 Artifactory 2026-09-02 N/A 5.3 MEDIUM
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-68754 1 Jfrog 1 Artifactory 2026-09-02 N/A 6.5 MEDIUM
A repository publisher without delete permission may modify protected package content under specific conditions.