Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
Potential unauthorized modification of Artifactory internal metadata
CVE-2026-65922
Description
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
Affected products
1Patches
Vulnerability mechanics
References
2- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesmitrevendor-advisory
- docs.jfrog.com/releases/docs/jfrog-security-advisoriesmitrevendor-advisory
News mentions
1- JFrog Zero-Days Exploited in OpenAI-Hugging Face HackSecurityWeek · Jul 29, 2026