Jfrog
42 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-69104
HIGH 7.6
Artifactory — An authenticated user may initiate repository migration operations without required repository permissions, po…
2026-08-25
CVE-2026-70548
LOW 3.5
Artifactory — Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory E…
2026-08-25
CVE-2026-70550
MEDIUM 6.5
Artifactory — An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, u…
2026-08-25
CVE-2026-70551
HIGH 8.5
Artifactory — A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute …
2026-08-25
CVE-2026-42018
HIGH 7.5
Artifactory — JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous ac…
2026-08-12
CVE-2026-65926
LOW 3.1
Artifactory — An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private…
2026-08-12
CVE-2026-66016
MEDIUM 6.7
Artifactory — Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifes…
2026-08-12
CVE-2026-66375
HIGH 8.1
Artifactory — A low-privilege authenticated user may permanently remove protected internal metadata across repositories unde…
2026-08-12
CVE-2026-66376
MEDIUM 4.2
Artifactory — Credentials for a deleted user may remain valid for a short period under specific conditions.
2026-08-12
CVE-2026-66377
MEDIUM 5.3
Artifactory — An unauthenticated user may access restricted repository information under specific conditions.
2026-08-12
CVE-2026-66378
MEDIUM 4.3
Artifactory — An authenticated user without repository read permission may access private NuGet metadata under specific cond…
2026-08-12
CVE-2026-66379
MEDIUM 4.3
Artifactory — An authenticated user may view private Puppet module metadata without repository read access.
2026-08-12
CVE-2026-66380
MEDIUM 4.3
Artifactory — An authenticated user without repository read permission may access private OCI referrer metadata under specif…
2026-08-12
CVE-2026-66381
MEDIUM 5.3
Artifactory — A repository reader with cache-deploy permission may access content outside a configured upstream path under s…
2026-08-12
CVE-2026-66382
MEDIUM 4.3
Artifactory — An authenticated user may write files outside the intended Artifactory work directory under specific condition…
2026-08-12
CVE-2026-66384
MEDIUM 5.3
Artifactory — An authenticated user may write data outside the intended Docker cache path under specific remote-repository c…● exploited
2026-08-12
CVE-2026-68752
HIGH 7.2
Artifactory — A Project Resource Manager may gain broader administrative privileges under specific conditions.
2026-08-12
CVE-2026-68753
MEDIUM 5.3
Artifactory — An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is con…
2026-08-12
CVE-2026-68754
MEDIUM 6.5
Artifactory — A repository publisher without delete permission may modify protected package content under specific condition…
2026-08-12
CVE-2026-68755
MEDIUM 4.3
Artifactory — A bundle writer may create misleading release promotion information under specific conditions.
2026-08-12
CVE-2026-68756
MEDIUM 6.6
Artifactory — A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
2026-08-12
CVE-2026-68757
HIGH 7.5
Artifactory — A user with access to a valid SAML response may impersonate another user under specific conditions.
2026-08-12
CVE-2026-68758
MEDIUM 6.5
Artifactory — A low-privileged authenticated user may access restricted support information under specific conditions.
2026-08-12
CVE-2026-68759
HIGH 7.2
Artifactory — A holder of a valid integration credential may impersonate other users under specific conditions.
2026-08-12
CVE-2026-68760
MEDIUM 5.3
Artifactory — An unauthenticated user may bypass authentication under specific cache conditions.
2026-08-12
CVE-2026-69105
HIGH 8.1
Artifactory — An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potent…
2026-08-12
CVE-2026-69106
HIGH 8.8
Artifactory — A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consu…
2026-08-12
CVE-2026-69107
MEDIUM 5.9
Artifactory — An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
2026-08-12
CVE-2026-70547
MEDIUM 4.3
Artifactory — An authenticated user without repository read permission may access package metadata under specific conditions…
2026-08-12
CVE-2026-42016
HIGH 8.1
Artifactory — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due t…
2026-07-27
CVE-2026-42017
HIGH 8.8
Artifactory — An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-priv…
2026-07-27
CVE-2026-65616
HIGH 8.8
Artifactory — Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog …
2026-07-27
CVE-2026-65617
HIGH 8.8
Artifactory — A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact c…
2026-07-27
CVE-2026-65618
MEDIUM 6.5
Artifactory — Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make una…
2026-07-27
CVE-2026-65921
HIGH 8.8
Artifactory — A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be …
2026-07-27
CVE-2026-65922
HIGH 7.1
Artifactory — An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repo…
2026-07-27
CVE-2026-65923
MEDIUM 6.8
Artifactory — A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific …
2026-07-27
CVE-2026-65924
MEDIUM 6.5
Artifactory — JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request…
2026-07-27
CVE-2026-65925
MEDIUM 6.5
Artifactory — A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended UR…
2026-07-27
CVE-2026-66014
HIGH 8.8
Artifactory — JFrog Artifactory contains an authentication handling weakness in internal request processing that, under spec…
2026-07-27
CVE-2026-66015
HIGH 7.2
Artifactory — An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned…
2026-07-27
CVE-2026-66018
MEDIUM 6.5
Artifactory — Build readers can access another repository's environment properties. A caller with read access to an ordinary…
2026-07-27