artifactory-self-managed-releases
by Jfrog
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82329 | Cri | 0.76 | 9.8 | 0.14 | KEV | Aug 28, 2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| CVE-2026-68758 | Med | 0.42 | 6.5 | 0.00 | Aug 12, 2026 | A low-privileged authenticated user may access restricted support information under specific conditions. | ||
| CVE-2026-66381 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | ||
| CVE-2026-66377 | Med | 0.34 | 5.3 | 0.00 | Aug 12, 2026 | An unauthenticated user may access restricted repository information under specific conditions. |
- risk 0.76cvss 9.8epss 0.14
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
- risk 0.42cvss 6.5epss 0.00
A low-privileged authenticated user may access restricted support information under specific conditions.
- risk 0.34cvss 5.3epss 0.00
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated user may access restricted repository information under specific conditions.