CVE-2026-65616
- EPSS 0.19%
- Veröffentlicht 27.07.2026 19:34:17
- Zuletzt bearbeitet 30.07.2026 14:49:28
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
CVE-2026-66015
- EPSS 0.39%
- Veröffentlicht 27.07.2026 19:33:27
- Zuletzt bearbeitet 30.07.2026 14:46:12
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVE-2026-65618
- EPSS 0.21%
- Veröffentlicht 27.07.2026 19:32:29
- Zuletzt bearbeitet 30.07.2026 14:51:10
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
CVE-2026-66018
- EPSS 0.23%
- Veröffentlicht 27.07.2026 19:31:34
- Zuletzt bearbeitet 30.07.2026 14:46:20
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environ...
CVE-2026-66014
- EPSS 0.32%
- Veröffentlicht 27.07.2026 19:29:47
- Zuletzt bearbeitet 30.07.2026 14:45:38
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-65921
- EPSS 0.37%
- Veröffentlicht 27.07.2026 19:27:31
- Zuletzt bearbeitet 30.07.2026 14:51:26
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
CVE-2026-42017
- EPSS 0.29%
- Veröffentlicht 27.07.2026 19:26:23
- Zuletzt bearbeitet 30.07.2026 14:41:34
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
CVE-2026-42016
- EPSS 0.23%
- Veröffentlicht 27.07.2026 19:20:56
- Zuletzt bearbeitet 30.07.2026 14:42:56
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2025-14830
- EPSS 0.24%
- Veröffentlicht 04.01.2026 09:17:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
CVE-2024-6915
- EPSS 0.6%
- Veröffentlicht 05.08.2024 20:15:36
- Zuletzt bearbeitet 15.04.2026 00:35:42
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.