CVE-2026-66016
- EPSS 0.08%
- Veröffentlicht 12.08.2026 15:16:39
- Zuletzt bearbeitet 12.08.2026 19:17:36
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-68759
- EPSS 0.23%
- Veröffentlicht 12.08.2026 15:15:50
- Zuletzt bearbeitet 12.08.2026 19:17:54
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-65926
- EPSS 0.19%
- Veröffentlicht 12.08.2026 15:14:42
- Zuletzt bearbeitet 12.08.2026 19:17:35
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
CVE-2026-66384
- EPSS 0.26%
- Veröffentlicht 12.08.2026 15:14:04
- Zuletzt bearbeitet 12.08.2026 19:17:37
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-68758
- EPSS 0.26%
- Veröffentlicht 12.08.2026 15:12:56
- Zuletzt bearbeitet 12.08.2026 19:17:53
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-65922
- EPSS 0.18%
- Veröffentlicht 27.07.2026 19:44:44
- Zuletzt bearbeitet 30.07.2026 14:43:18
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availab...
CVE-2026-65923
- EPSS 0.19%
- Veröffentlicht 27.07.2026 19:43:46
- Zuletzt bearbeitet 30.07.2026 14:44:14
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has be...
CVE-2026-65617
- EPSS 0.31%
- Veröffentlicht 27.07.2026 19:37:27
- Zuletzt bearbeitet 30.07.2026 14:49:42
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVE-2026-65924
- EPSS 0.22%
- Veröffentlicht 27.07.2026 19:36:35
- Zuletzt bearbeitet 30.07.2026 14:44:38
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifac...
CVE-2026-65925
- EPSS 0.21%
- Veröffentlicht 27.07.2026 19:35:17
- Zuletzt bearbeitet 30.07.2026 14:45:18
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.