Artifactory
by Jfrog
Source repositories
CVEs (65)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65618 | Med | 0.00 | 6.5 | 0.00 | Jul 27, 2026 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data. | ||
| CVE-2026-65617 | Hig | 0.00 | 8.8 | 0.00 | Jul 27, 2026 | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | ||
| CVE-2026-65616 | Hig | 0.00 | 8.8 | 0.00 | Jul 27, 2026 | Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. | ||
| CVE-2026-42017 | Hig | 0.00 | 8.8 | 0.00 | Jul 27, 2026 | An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. | ||
| CVE-2026-42016 | Hig | 0.00 | 8.1 | 0.00 | Jul 27, 2026 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. |
- risk 0.00cvss 6.5epss 0.00
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
- risk 0.00cvss 8.8epss 0.00
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- risk 0.00cvss 8.8epss 0.00
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
- risk 0.00cvss 8.8epss 0.00
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
- risk 0.00cvss 8.1epss 0.00
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Page 4 of 4