8.8
CVE-2026-65617
- EPSS 0.31%
- Veröffentlicht 27.07.2026 19:37:27
- Zuletzt bearbeitet 30.07.2026 14:49:42
- CVE-Watchlists
- Unerledigt
Potential remote code execution on an Artifactory package service container.
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jfrog ≫ Artifactory SwPlatform- Version < 7.111.18
Jfrog ≫ Artifactory SwPlatform- Version >= 7.117.0 < 7.117.25
Jfrog ≫ Artifactory SwPlatform- Version >= 7.125.0 < 7.125.18
Jfrog ≫ Artifactory SwPlatform- Version >= 7.133.0 < 7.133.27
Jfrog ≫ Artifactory SwPlatform- Version >= 7.146.0 < 7.146.34
Jfrog ≫ Artifactory SwPlatform- Version >= 7.161.0 < 7.161.15
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.236 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| reefs@jfrog.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases