CVE-2026-65922
- EPSS 0.18%
- Veröffentlicht 27.07.2026 19:44:44
- Zuletzt bearbeitet 30.07.2026 14:43:18
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availab...
CVE-2026-65923
- EPSS 0.19%
- Veröffentlicht 27.07.2026 19:43:46
- Zuletzt bearbeitet 30.07.2026 14:44:14
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has be...
CVE-2026-65617
- EPSS 0.31%
- Veröffentlicht 27.07.2026 19:37:27
- Zuletzt bearbeitet 30.07.2026 14:49:42
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVE-2026-65924
- EPSS 0.22%
- Veröffentlicht 27.07.2026 19:36:35
- Zuletzt bearbeitet 30.07.2026 14:44:38
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifac...
CVE-2026-65925
- EPSS 0.21%
- Veröffentlicht 27.07.2026 19:35:17
- Zuletzt bearbeitet 30.07.2026 14:45:18
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
CVE-2026-65616
- EPSS 0.19%
- Veröffentlicht 27.07.2026 19:34:17
- Zuletzt bearbeitet 30.07.2026 14:49:28
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
CVE-2026-66015
- EPSS 0.39%
- Veröffentlicht 27.07.2026 19:33:27
- Zuletzt bearbeitet 30.07.2026 14:46:12
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVE-2026-65618
- EPSS 0.21%
- Veröffentlicht 27.07.2026 19:32:29
- Zuletzt bearbeitet 30.07.2026 14:51:10
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
CVE-2026-66018
- EPSS 0.23%
- Veröffentlicht 27.07.2026 19:31:34
- Zuletzt bearbeitet 30.07.2026 14:46:20
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environ...
CVE-2026-66014
- EPSS 0.32%
- Veröffentlicht 27.07.2026 19:29:47
- Zuletzt bearbeitet 15.09.2026 18:30:26
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.