JFrogCVE-2026-70550
JFrog artifactory: missing authorization
Medium6.5CVE-2026-70550 · Published Aug 25, 2026 · updated Aug 28, 2026
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| artifactory Product | >= 7.161.0, < 7.161.19 | 7.161.19 |
| >= 7.146.0, < 7.146.29 | 7.146.29 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More JFrog advisories
All JFrog| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | JFrog artifactory: improper authentication | Critical9.8 | 7.111.21+3 more |
| Aug 25 | JFrog artifactory: server-side request forgery | Low3.5 | 7.161.19+1 more |
| Aug 25 | JFrog artifactory: server-side request forgery | High8.5 | 7.161.19+1 more |
| Aug 25 | JFrog artifactory: information disclosure | High7.6 | 7.161.19 |
| Aug 12 | JFrog artifactory: improper input validation | High8.8 | 7.146.28 |
| Aug 12 | JFrog artifactory: improper authentication | High7.5 | 7.111.20+3 more |