VYPR
patchPublished Aug 25, 2026· Updated Aug 28, 2026· 1 source

JFrog Artifactory: Three Auth and Repo Handling Flaws Disclosed Together

Key findings • Three vulnerabilities in JFrog Artifactory disclosed on August 25, 2026. • Two high-severity flaws impact VCS repository handling and migration operations. • Medium-severit…

Key findings

  • Three vulnerabilities in JFrog Artifactory disclosed on August 25, 2026.
  • Two high-severity flaws impact VCS repository handling and migration operations.
  • Medium-severity bug allows unauthorized access to Composer repository metadata.
  • JFrog has released patches for the affected Artifactory versions.

On August 25, 2026, JFrog disclosed three vulnerabilities affecting its Artifactory software. The batch of CVEs, disclosed within a one-hour window, includes two high-severity flaws and one medium-severity issue, primarily impacting authorization and data handling within Artifactory's repository management features.

Two of the vulnerabilities, CVE-2026-70551 and CVE-2026-69104, are rated as High severity. CVE-2026-70551 allows a user with read access to an existing remote VCS repository to potentially alter its origin or supply an absolute VCS data URL. This could lead to unauthorized code execution or manipulation of version control data. CVE-2026-69104 enables an authenticated user to initiate repository migration operations without the necessary permissions. This could result in information disclosure, unauthorized modifications to repository states, or service disruptions.

The third vulnerability, CVE-2026-70550, is a Medium severity issue stemming from an authorization weakness in how Artifactory handles Composer repositories. Under specific conditions, an authenticated user could read package metadata from repositories for which they lack explicit authorization, impacting data confidentiality.

JFrog has addressed these vulnerabilities in updated versions of Artifactory. Users are advised to consult JFrog's security advisories for specific version information and apply the necessary patches to mitigate these risks. The timely disclosure and patching of these issues are crucial for maintaining the security and integrity of software supply chains managed through Artifactory.

Synthesized by Vypr AI