Total
70 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66014 | 1 Jfrog | 1 Artifactory | 2026-09-15 | N/A | 8.8 HIGH |
| JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. | |||||
| CVE-2026-42018 | 1 Jfrog | 1 Artifactory | 2026-09-12 | N/A | 7.5 HIGH |
| JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | |||||
| CVE-2026-42016 | 1 Jfrog | 1 Artifactory | 2026-09-12 | N/A | 8.1 HIGH |
| JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | |||||
| CVE-2026-66016 | 1 Jfrog | 1 Artifactory | 2026-09-11 | N/A | 6.7 MEDIUM |
| Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | |||||
| CVE-2026-69105 | 1 Jfrog | 1 Artifactory | 2026-09-11 | N/A | 8.1 HIGH |
| An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | |||||
| CVE-2026-69107 | 1 Jfrog | 1 Artifactory | 2026-09-11 | N/A | 5.9 MEDIUM |
| An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |||||
| CVE-2026-70547 | 1 Jfrog | 1 Artifactory | 2026-09-11 | N/A | 4.3 MEDIUM |
| An authenticated user without repository read permission may access package metadata under specific conditions. | |||||
| CVE-2026-69106 | 1 Jfrog | 1 Artifactory | 2026-09-11 | N/A | 8.8 HIGH |
| A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |||||
| CVE-2026-82329 | 1 Jfrog | 1 Artifactory | 2026-09-03 | N/A | 9.8 CRITICAL |
| JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |||||
| CVE-2026-66375 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 8.1 HIGH |
| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | |||||
| CVE-2026-66376 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.2 MEDIUM |
| Credentials for a deleted user may remain valid for a short period under specific conditions. | |||||
| CVE-2026-66377 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 5.3 MEDIUM |
| An unauthenticated user may access restricted repository information under specific conditions. | |||||
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | |||||
| CVE-2026-66379 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user may view private Puppet module metadata without repository read access. | |||||
| CVE-2026-66380 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | |||||
| CVE-2026-66381 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 5.3 MEDIUM |
| A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | |||||
| CVE-2026-66382 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | |||||
| CVE-2026-68752 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 7.2 HIGH |
| A Project Resource Manager may gain broader administrative privileges under specific conditions. | |||||
| CVE-2026-68753 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 5.3 MEDIUM |
| An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | |||||
| CVE-2026-68754 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.5 MEDIUM |
| A repository publisher without delete permission may modify protected package content under specific conditions. | |||||
