Skip to content
JFrogCVE-2026-70550

JFrog artifactory: missing authorization

Medium6.5CVE-2026-70550 · Published Aug 25, 2026 · updated Aug 28, 2026

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
>= 7.161.0, < 7.161.197.161.19
>= 7.146.0, < 7.146.297.146.29
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: improper authentication
Critical9.8Aug 28
JFrog artifactory: server-side request forgery
Low3.5Aug 25
JFrog artifactory: server-side request forgery
High8.5Aug 25
JFrog artifactory: information disclosure
High7.6Aug 25
JFrog artifactory: improper input validation
High8.8Aug 12
JFrog artifactory: improper authentication
High7.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.