JFrog Security Advisories

JFrog security advisories and CVE information for Artifactory vulnerabilities, with detailed information on affected versions and remediation guidance.

Support

For support inquiries, visit JFrog Support.

JFrog takes the privacy and security of its customers very seriously and always strives to provide prompt notification and remediation of any vulnerabilities discovered on JFrog products. As a CVE Numbering Authority (CNA), JFrog assigns CVE identification numbers to newly discovered security vulnerabilities.

Security Advisories

SeverityCVESummaryProductVersionsPublishedUpdated
CriticalCVE-2026-82329Potential authentication bypass leading to administrative access in Artifactory.Artifactory7.161.0 > 7.161.19
7.146.0 > 7.146.36
7.133.0 > 7.133.28
7.125.0 > 7.125.19
7.117.0 > 7.117.27
7.111.4 > 7.111.21
28 Aug 202628 Aug 2026
HighCVE-2026-70551Server-Side Request Forgery Via VCS remote download in JFrog Artifactory.Artifactory7.161.0 > 7.161.16
7.146.0 > 7.146.35
25 Aug 202625 Aug 2026
MediumCVE-2026-70550An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user to read package metadata from repositories they are not authorized to read.Artifactory7.161.0 > 7.161.11
7.146.0 > 7.146.35
25 Aug 202625 Aug 2026
LowCVE-2026-70548Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External DependencyArtifactory7.161.0 > 7.161.1
7.161.11 > 7.161.16
7.146.0 > 7.146.29
25 Aug 202625 Aug 2026
HighCVE-2026-69104An authenticated user may initiate repository migration operations without required repository permissions.Artifactory7.161.0 > 7.161.1825 Aug 202625 Aug 2026
MediumCVE-2026-70547An authenticated user without repository read permission may access package metadata.Artifactory7.161.0 –> 7.161.1612 Aug 202613 Aug 2026
HighCVE-2026-69105An unauthenticated attacker may cause untrusted package content to be cached, affecting artifact integrity and availability.Artifactory7.161.0 –> 7.161.1612 Aug 202613 Aug 2026
MediumCVE-2026-69107An unauthenticated user may access restricted artifacts under specific conditions.Artifactory< 7.104.16;
7.111.0 –>7.111.14; 7.117.0 –> 7.117.21; 7.125.0 -> 7.125.14; 7.133.0 –> 7.133.21; 7.146.0 –> 7.146.8
12 Aug 202612 Aug 2026
HighCVE-2026-69106A low-privileged user may poison cached artifact metadata, potentially causing retrieval of untrusted content.Artifactory<7.146.2812 Aug 202613 Aug 2026
HighCVE-2026-42018Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.Artifactory< 7.111.20;
7.117.0 –> 7.117.27;
7.125.0 –> 7.125.19;
7.133.0 –> 7.133.28;
7.146.0 –> 7.146.8
12 Aug 202613 Aug 2026
MediumCVE-2026-66384An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.Artifactory<7.146.35;
7.161.0 -> 7.161.16
12 Aug 202612 Aug 2026
HighCVE-2026-66375A low-privilege authenticated user may permanently remove protected internal metadata across repositories.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66016Generated TLS private keys may be retained in rendered Helm manifests accessible to highly privileged local users.Artifactory< 7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
LowCVE-2026-65926An anonymous or low-privilege user may learn private Release Bundle names and versions when the bundle name is known.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-68760An unauthenticated user may bypass authentication under specific cache conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66378An authenticated user without repository read permission may access private NuGet metadata.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202613 Aug 2026
MediumCVE-2026-66380An authenticated user without repository read permission may access private OCI referrer metadata.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66381A repository reader with cache-deploy permission may access content outside a configured upstream path.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66382An authenticated user may write files outside the intended Artifactory work directory.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66376Credentials for a deleted user may remain valid for a short period under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-68754A repository publisher without delete permission may modify protected package content.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
HighCVE-2026-68757A user with access to a valid SAML response may impersonate another user under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-68756A party with write access to stored session data may affect Artifactory under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202613 Aug 2026
HighCVE-2026-68752A Project Resource Manager may gain broader administrative privileges under specific conditions.Artifactory< 7.146.3512 Aug 202613 Aug 2026
MediumCVE-2026-68755A bundle writer may create misleading release-promotion information under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-68753An unauthenticated user may access restricted content when a credentialed remote repository is configured in a specific way.Artifactory< 7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
HighCVE-2026-68759A holder of a valid integration credential may impersonate other users under specific conditions.Artifactory< 7.146.35;
7.161.0–> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-68758A low-privileged authenticated user may access restricted support information under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202612 Aug 2026
MediumCVE-2026-66377An unauthenticated user may access restricted repository information under specific conditions.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202613 Aug 2026
MediumCVE-2026-66379An authenticated user may view private Puppet module metadata without repository read access.Artifactory<7.146.35;
7.161.0 –> 7.161.16
12 Aug 202613 Aug 2026
MediumCVE-2026-65924Terraform remote repositories could issue outbound requests to arbitrary destinations and return response content.Artifactory<7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
HighCVE-2026-66015An authenticated authorization flaw may grant temporary platform administrator access.Artifactory7.146.0 –> 7.146.34; 7.161.0 –> 7.161.1527 Jul 202627 Jul 2026
HighCVE-2026-66014An internal request authentication weakness may allow privilege escalation under specific conditions.Artifactory<7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
MediumCVE-2026-66018Build readers can access another repository's environment properties, potentially exposing build secrets.Artifactory7.146.0 –> 7.146.34; 7.161.0 –> 7.161.1527 Jul 202627 Jul 2026
MediumCVE-2026-65923An Ansible repository URL-validation weakness could cause unintended server-side requests.Artifactory< 7.111.18;
7.117.0–> 7.117.25;
7.125.0–> 7.125.18;
7.133.0–> 7.133.27;
7.146.0–> 7.146.34;
7.161.0–> 7.161.15
27 Jul 202627 Jul 2026
HighCVE-2026-65922An authorization weakness could let a limited repository user write to restricted internal metadata areas.Artifactory<7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
HighCVE-2026-65921Archive path validation allows traversal entries to be written outside the intended build-artifacts location.Artifactory< 7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
MediumCVE-2026-65925A user with Cargo remote-repository read access could make Artifactory request unintended URLs and return the response.Artifactory< 7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
HighCVE-2026-65617A package-handling deserialization weakness could let a low-privileged user affect confidentiality, integrity, and availability.Artifactory< 7.111.18;
7.117.0 –> 7.117.25;
7.125.0 –> 7.125.18;
7.133.0 –> 7.133.27;
7.146.0 –> 7.146.34;
7.161.0 –> 7.161.15
27 Jul 202627 Jul 2026
HighCVE-2026-65616Incorrect refresh-token signature validation allows non-admin users to obtain a signed administrator token.Artifactory< 7.146.2727 Jul 202627 Jul 2026
HighCVE-2026-42017An event-handling weakness could expose privileged authorization material to a lower-privileged user.Artifactory< 7.133.21;
7.146.0 –> 7.146.8
27 Jul 202627 Jul 2026
HighCVE-2026-42016JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.Artifactory<7.133.1127 Jul 202627 Jul 2026
MediumCVE-2026-65618Improper URL validation when handling specific URLs allows unauthorized requests from Artifactory, potentially exposing internal services and cached response data.Artifactory<7.133.627 Jul 202627 Jul 2026
MediumCVE-2025-14830JFrog Artifactory is vulnerable to improper handling of import Validation Mechanism which could lead to DOM-based cross-site scripting.ArtifactoryArtifactory Self Hosted < 7.94.0 > 7.117.104 Jan 264 Jan 26
CriticalCVE-2024-6915JFrog Artifactory is vulnerable to Improper Input Validation that could potentially lead to Cache Poisoning.ArtifactoryArtifactory Self Hosted < 7.90.6, < 7.84.20, < 7.77.14, < 7.71.23, < 7.68.22, < 7.63.22, < 7.59.23, < 7.55.185 Aug 245 Aug 24
MediumCVE-2024-2248A Header Injection vulnerability in the JFrog platform may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim's user email.ArtifactorySaaS versions prior to 7.85.0, Self-Hosted version prior to 7.84.715 May 2415 May 24
CriticalCVE-2024-4142An Improper input validation vulnerability was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system, an issue that could potentially lead to privilege escalation. This issue can also be exploited in Artifactory platforms with anonymous access enabled.ArtifactoryArtifactory Self-Hosted < 7.55.17, < 7.59.22, < 7.63.21, < 7.68.21, < 7.71.21, < 7.77.11; Artifactory Cloud < 7.84.61 May 241 May 24
MediumCVE-2024-3505JFrog Artifactory Self-Hosted versions prior to 7.77.3 are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.ArtifactorySelf-hosted versions prior to 7.77.311 Apr 2411 Apr 24
HighCVE-2024-2247JFrog Artifactory prior to version 7.77.7, is vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.ArtifactoryVersions prior to 7.77.713 Mar 2413 Mar 24
HighCVE-2023-42661JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.ArtifactoryVersions prior to 7.76.27 Mar 247 Mar 24
MediumCVE-2023-42509JFrog Artifactory later than version 7.17.4 and prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.ArtifactoryVersions later than 7.17.4 but prior to version 7.77.07 Mar 247 Mar 24
CriticalCVE-2023-42662JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.ArtifactoryVersions later than 7.59 but prior to: 7.59.18, 7.63.18, 7.68.19, 7.71.86 Mar 246 Mar 24
MediumCVE-2023-42508JFrog Artifactory prior to version 7.66.0, is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.ArtifactoryVersions prior to 7.66.010/04/202310/04/2023
MediumCVE-2022-0668JFrog Artifactory prior to versions 7.37.13 and 6.23.41. is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.ArtifactoryVersions prior to 7.37.13, Versions prior to 6.23.4101/02/202301/02/2023
MediumCVE-2021-45721JFrog Artifactory prior to version 7.29.8 and 6.23.38is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in the Users REST API endpoint.ArtifactoryVersions prior to 7.29.8, Versions prior to 6.23.3807/05/202207/05/2022
MediumCVE-2021-46687JFrog Artifactory prior to version 7.31.10and 6.23.38is vulnerable to Sensitive Data Exposure through the Project Administrator REST API.ArtifactoryVersions prior to 7.31.10, Versions prior to 6.23.3807/05/202207/05/2022
LowCVE-2021-23163JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints.ArtifactoryVersions prior to 7.33.6, Versions prior to 6.23.3807/05/202207/05/2022
MediumCVE-2021-41834JFrog Artifactory prior to versions 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user can use the copy function to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.ArtifactoryVersions prior to 7.28.0, Versions prior to 6.23.3805/18/202205/18/2022
MediumCVE-2021-45730JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.ArtifactoryVersions prior to 7.31.1005/18/202205/18/2022
HighCVE-2022-0573JFrog Artifactory prior to 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation, and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.ArtifactoryVersions prior to 7.36.1, Versions prior to 6.34.4105/12/202205/12/2022
LowCVE-2021-46270JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.ArtifactoryVersions prior to 7.31.1003/02/202203/02/2022
MediumCVE-2021-45074JFrog Artifactory prior to7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users'OAuthtoken, which will force a reauthentication on an active session or in the following UI session.ArtifactoryVersions prior to 7.29.3, Versions prior to 6.23.3803/02/202203/02/2022
HighCVE-2021-3860JFrog Artifactory prior to version 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.ArtifactoryVersions prior to 7.25.4, Versions prior to 6.23.3012/15/202112/15/2021

CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-82329CriticalCWE-287 Improper Authentication28 Aug 202628 Aug 2026

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 > 7.161.197.161.20
Artifactory7.146.0 > 7.146.367.146.38
Artifactory7.133.0 > 7.133.287.133.29
Artifactory7.125.0 > 7.125.197.125.20
Artifactory7.117.0 > 7.117.277.117.28
Artifactory7.111.4 > 7.111.217.111.21

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20

Workarounds and Mitigations

The best known remediation is to upgrade to the patched version above.

However, if you are unable to upgrade rapidly, we recommend the following workaround to reduce risk to your systems.

An additional join key is a random, hex-encoded value in the same format as your join key. Generate one with any of the following:

# Option A: OpenSSL (recommended)
openssl rand -hex 16

# Option B: Python
python3 -c "import secrets; print(secrets.token_hex(16))"

Example output (do not reuse this — generate your own): 3f8c1a9b0d2e4f6a7b8c9d0e1f2a3b4c

Keep this value secret, the same way you protect your join key.

To apply it:

  1. Edit your system.yaml and add the generated additionalJoinKeys value under shared › security:
    shared:
      security:
        ## Existing join key stays as-is; just add the line below.
        ## Use a strong, random value in the same format as your join key.
        additionalJoinKeys: "<your-strong-random-join-key-value>"
    • If you already have entries under shared: security: (for example, joinKey), keep them and simply add the additionalJoinKeys line — do not duplicate the shared: or security: headings.
    • For more than one key, use a comma-separated list: additionalJoinKeys: "key1,key2"
    • Containerized / Helm deployments can set the equivalent environment variable instead: JF_SHARED_SECURITY_ADDITIONALJOINKEYS.
  2. Restart the Access service (or the JPD) for the change to take effect.

This workaround is designed to enforce that only your own keys are accepted for service registration. Your existing join key continues to work, so cluster operation is unaffected.

CVE-2026-70551 - Server-Side Request Forgery Via VCS Remote Download

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-70551HighCWE-918 - Server-Side Request Forgery (SSRF)25 Aug 202625 Aug 2026

Description

A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 > 7.161.177.161.19
Artifactory7.146.0 > 7.146.357.146.36

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.19 or 7.146.36.

CVE-2026-70550 - Potential unauthorized access to private Composer repository metadata in JFrog Artifactory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-70550MediumCWE-862 Missing Authorization25 Aug 202625 Aug 2026

Description

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 > 7.161.117.161.19
Artifactory0 > 7.146.297.146.36

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.19 or 7.146.36.

CVE-2026-70548 - SSRF In CocoaPods Via JFrog Artifactory External Dependency

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-70548LowCWE-918 - Server-Side Request Forgery (SSRF)25 Aug 202625 Aug 2026

Description

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 > 7.161.17.161.19
Artifactory7.161.11 > 7.161.167.161.19
Artifactory7.146.0 > 7.146.297.146.36

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.19 or 7.146.36.

CVE-2026-69104 - Potential unauthorized repository migration in JFrog Artifactory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-69104HighCWE-862 Missing Authorization25 Aug 202625 Aug 2026

Description

An authenticated user may initiate repository migration operations without required repository permissions, potentially causing partial information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 > 7.161.187.161.19

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.19.

CVE-2026-70547 - Potential Unauthorized Metadata Exposure

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-70547MediumCWE-862 Missing Authorization12 Aug 202613 Aug 2026

Description

An authenticated user without repository read permission may access package metadata.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.16.

CVE-2026-69105 - Potential Package Cache Integrity Issue

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-69105HighCWE-345 Insufficient Verification of Data Authenticity12 Aug 202613 Aug 2026

Description

An unauthenticated attacker may cause untrusted package content to be cached, affecting artifact integrity and availability.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.161.0 -> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.161.16.

CVE-2026-69107 - Potential Unauthorized Artifact Access

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-69107MediumCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

An unauthenticated user may access restricted artifacts under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.104.167.104.16
Artifactory7.111.0 –> 7.111.147.111.14
Artifactory7.117.0 –> 7.117.217.117.21
Artifactory7.125.0 –> 7.125.147.125.14
Artifactory7.133.0 –> 7.133.217.133.21
Artifactory7.146.0 –> 7.146.87.146.8

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.104.16, 7.111.14, 7.117.21, 7.125.14, 7.133.21, 7.146.8.

CVE-2026-69106 - Potential Cache Poisoning in JFrog Artifactory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-69106HighCWE-20 Improper Input Validation12 Aug 202613 Aug 2026

Description

A low-privileged user may poison cached artifact metadata, potentially causing retrieval of untrusted content.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.287.146.28

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.28.

CVE-2026-42018 - Anonymous User Token Generation Exposure

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-42018HighCWE-287 Improper Authentication12 Aug 202613 Aug 2026

Description

Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.111.207.111.20
Artifactory7.117.0–>7.117.277.117.27
Artifactory7.125.0–>7.125.197.125.19
Artifactory7.133.0–>7.133.287.133.28
Artifactory7.146.0–>7.146.87.146.8

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.20, 7.117.27, 7.125.19, 7.133.28, 7.146.8.

CVE-2026-66384 - Authenticated Users May Write Data Outside the Intended Docker Cache Path


CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66384MediumCWE-22 Improper Limitation of a Pathname to a Restricted Directory12 Aug 202612 Aug 2026

Description

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0–> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66375 - Low-Privilege Users May Remove Protected Artifactory Metadata

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66375HighCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

A low-privilege authenticated user may permanently remove protected internal metadata across repositories.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66016 - Rendered Helm Manifests May Contain Generated TLS Private Keys

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66016MediumCWE-312 Cleartext Storage of Sensitive Information12 Aug 202612 Aug 2026

Description

Generated TLS private keys may be retained in rendered Helm manifests accessible to highly privileged local users.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-65926 - Private Release Bundle Versions May Be Disclosed

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65926LowCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

An anonymous or low-privilege user may learn private Release Bundle names and versions when the bundle name is known.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68760 - Potential Remember-Me Authentication Bypass

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68760MediumCWE-287 Improper Authentication12 Aug 202612 Aug 2026

Description

An unauthenticated user may bypass authentication under specific cache conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66378 - Authenticated Users May Access Private NuGet Metadata

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66378MediumCWE-862 Missing Authorization12 Aug 202613 Aug 2026

Description

An authenticated user without repository read permission may access private NuGet metadata.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66380 - Authenticated Users May Access Private OCI Referrer Metadata

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66380MediumCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

An authenticated user without repository read permission may access private OCI referrer metadata.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66381 - Repository Readers May Access Content Outside Configured Upstream Paths

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66381MediumCWE-22 Improper Limitation of a Pathname to a Restricted Directory12 Aug 202612 Aug 2026

Description

A repository reader with cache-deploy permission may access content outside a configured upstream path.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66382 - Authenticated Users May Write Files Outside the Intended Work Directory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66382MediumCWE-22 Improper Limitation of a Pathname to a Restricted Directory12 Aug 202612 Aug 2026

Description

An authenticated user may write files outside the intended Artifactory work directory.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66376 - Deleted Users May Temporarily Retain Access

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66376MediumCWE-613 Insufficient Session Expiration12 Aug 202612 Aug 2026

Description

Credentials for a deleted user may remain valid for a short period under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68754 - Publishers Without Delete Permission Can Overwrite Docker Layer Information

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68754MediumCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

A repository publisher without delete permission may modify protected package content.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68757 - Potential Improper SAML Signature Verification

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68757HighCWE-347 Improper Verification of Cryptographic Signature12 Aug 202612 Aug 2026

Description

A user with access to a valid SAML response may impersonate another user under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68756 - Potential Insecure Deserialization in JFrog Artifactory

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68756MediumCWE-502 Deserialization of Untrusted Data12 Aug 202613 Aug 2026

Description

A party with write access to stored session data may affect Artifactory under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68752 - Project Resource Managers May Escalate Privileges

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68752HighCWE-269 Improper Privilege Management12 Aug 202613 Aug 2026

Description

A Project Resource Manager may gain broader administrative privileges under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35.

CVE-2026-68755 - Bundle Writers May Alter Trusted Release Information

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68755MediumCWE-863 Incorrect Authorization12 Aug 202612 Aug 2026

Description

A bundle writer may create misleading release-promotion information under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68753 - Anonymous Users May Access Restricted Content Under Specific Configurations

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68753MediumCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

An unauthenticated user may access restricted content when a credentialed remote repository is configured in a specific way.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68759 - Integration Credential Holders May Impersonate Users

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68759HighCWE-347 Improper Verification of Cryptographic Signature12 Aug 202612 Aug 2026

Description

A holder of a valid integration credential may impersonate other users under specific conditions.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-68758 - Authenticated Users May Access Restricted Support Information

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-68758MediumCWE-862 Missing Authorization12 Aug 202612 Aug 2026

Description

A low-privileged authenticated user may access restricted support information under specific conditions.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66377 - Anonymous Users May Access Restricted Repository Information

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66377MediumCWE-862 Missing Authorization12 Aug 202613 Aug 2026

Description

An unauthenticated user may access restricted repository information under specific conditions.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-66379 - Authenticated Users May View Private Puppet Module Metadata

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66379MediumCWE-862 Missing Authorization12 Aug 202613 Aug 2026

Description

An authenticated user may view private Puppet module metadata without repository read access.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.146.357.146.35
Artifactory7.161.0 –> 7.161.167.161.16

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.35, 7.161.16.

CVE-2026-65924 - Server-Side Request Forgery via Terraform Remote Repository

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65924MediumCWE-918 Server-Side Request Forgery (SSRF)27 Jul 202627 Jul 2026

Description

Terraform remote repositories could issue outbound requests to arbitrary destinations and return response content.

Affected Products

ProductAffected VersionsPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-66015 - Authorization Flaw May Allow Authenticated Privilege Escalation

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66015HighCWE-269 Improper Privilege Management27 Jul 202627 Jul 2026

Description

An authenticated authorization flaw may grant temporary platform administrator access.

Affected Products

ProductAffected VersionsPatched Version
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.34, 7.161.15.

CVE-2026-66014 - Potential Authentication Bypass Leading to Privilege Escalation

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66014HighCWE-287 Improper Authentication27 Jul 202627 Jul 2026

Description

An internal request authentication weakness may allow privilege escalation under specific conditions.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-66018 - JFrog Artifactory Build Environment Properties Exposure

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-66018MediumCWE-200 Exposure of Sensitive Information to an Unauthorized Actor27 Jul 202627 Jul 2026

Description

Build readers can access another repository's environment properties, potentially exposing build secrets.

Affected Products

ProductAffected VersionPatched Version
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.34, 7.161.15.

CVE-2026-65923 - Potential SSRF in Artifactory Ansible Repository Handling

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65923MediumCWE-918 Server-Side Request Forgery (SSRF)27 Jul 202627 Jul 2026

Description

An Ansible repository URL-validation weakness could cause unintended server-side requests.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-65922 - Potential Unauthorized Modification of Artifactory Internal Metadata

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65922HighCWE-862 Missing Authorization27 Jul 202627 Jul 2026

Description

An authorization weakness could let a limited repository user write to restricted internal metadata areas.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-65921 - Potential Path Traversal Leading to Unauthorized File Writes

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65921HighCWE-22 Improper Limitation of a Pathname to a Restricted Directory27 Jul 202627 Jul 2026

Description

Archive path validation allows traversal entries to be written outside the intended build-artifacts location.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0–<7.125.187.125.18
Artifactory7.133.0–<7.133.277.133.27
Artifactory7.146.0–<7.146.347.146.34
Artifactory7.161.0–<7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-65925 - Server-Side Request Forgery via Artifactory Cargo Remote Repository

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65925MediumCWE-918 Server-Side Request Forgery (SSRF)27 Jul 202627 Jul 2026

Description

A user with Cargo remote-repository read access could make Artifactory request unintended URLs and return the response.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-65617 - Potential Remote Code Execution on an Artifactory Package Service Container

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65617HighCWE-502 Deserialization of Untrusted Data27 Jul 202627 Jul 2026

Description

A package-handling deserialization weakness could let a low-privileged user affect confidentiality, integrity, and availability.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.111.187.111.18
Artifactory7.117.0 –> 7.117.257.117.25
Artifactory7.125.0 –> 7.125.187.125.18
Artifactory7.133.0 –> 7.133.277.133.27
Artifactory7.146.0 –> 7.146.347.146.34
Artifactory7.161.0 –> 7.161.157.161.15

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

CVE-2026-65616 - Potential Privilege Escalation to JFrog Administrator Privileges

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65616HighCWE-347 Improper Verification of Cryptographic Signature27 Jul 202627 Jul 2026

Description

Incorrect refresh-token signature validation allows non-admin users to obtain a signed administrator token.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.146.277.146.27

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.146.27.

CVE-2026-42017 - Privilege Escalation via JFrog Worker Event Token Exposure

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-42017HighCWE-200 Exposure of Sensitive Information to an Unauthorized Actor27 Jul 202627 Jul 2026

Description

An event-handling weakness could expose privileged authorization material to a lower-privileged user.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.133.217.133.21
Artifactory7.146.0 –> 7.146.87.146.8

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.133.21, 7.146.8.

CVE-2026-42016 - Incorrect User Token Authorization Validation Allows Privilege Escalation

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-42016HighCWE-863 Incorrect Authorization27 Jul 202627 Jul 2026

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.133.117.133.11

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.133.11.

CVE-2026-65618 - Improper URL Validation May Lead to SSRF

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2026-65618MediumCWE-918 Server-Side Request Forgery (SSRF)27 Jul 202627 Jul 2026

Description

Improper URL validation when handling specific URLs allows unauthorized requests from Artifactory, potentially exposing internal services and cached response data.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.133.67.133.6

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.133.6.

CVE-2025-14830 - Improper Handling of Import Validation Mechanism Could Lead to DOM-based Cross-site Scripting

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2025-14830MediumCWE-79 Improper AuthenticationJanuary 4, 2026January 4, 2026

Description

JFrog Artifactory versions later than 7.94.0 but prior to version 7.117.10 (Enterprise+ and Enterprise X deployments only), are vulnerable to DOM-based cross-site scripting due to improper handling of the import validation mechanism.

Affected Products

ProductAffected VersionPatched Version
ArtifactoryVersions greater than 7.94.0 but less than 7.117.107.117.10

How to Fix

  • Cloud Environment: Affected Cloud environments have already been fortified. No action is required for cloud instances.
  • Self-Hosted Environment: Upgrade to version 7.117.10

Workarounds and Mitigations

Users can block the Workers functionality:

  • Block /ui/admin/workers/ path on WAF
  • Uninstall Workers

CVE-2024-6915 - Cache Poisoning

CVE IdentifierSeverityCWE Weakness TypeDate PublishedDate Updated
CVE-2024-6915CriticalCWE-20August 5, 2024August 5, 2024

Description

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, and 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to Cache Poisoning.

Affected Products

ProductAffected VersionPatched Version
Artifactory< 7.90.67.90.6
Artifactory< 7.84.207.84.20
Artifactory< 7.77.147.77.14
Artifactory< 7.71.237.71.23
Artifactory< 7.68.227.68.22
Artifactory< 7.63.227.63.22
Artifactory< 7.59.237.59.23
Artifactory< 7.55.187.55.18

How to Fix

  • Self Hosted: To fix this issue, upgrade using the security patch for your required Patched Version from the following location: https://jfrog.com/download-legacy/

  • Cloud:

    • Environments have already been updated to a fixed version containing additional security controls. No action is required for cloud instances.
    • Cloud customers with Hybrid deployments where their Edge resides on-premise will need to upgrade their on-premise Edge instance

Workarounds and Mitigations

Disable anonymous access or remove Deploy/Cache permissions for remote repositories for the Anonymous account.

Acknowledgements

This issue was discovered and reported by Michael Stepankin (artsploit) from GitHub Security Lab.

CVE-2024-2248 - JFrog Artifactory Header Injection

CVE IdentifierSeverityCWE / Weakness TypeDate PublishingDate Updated
CVE-2024-2248MediumCWE-20 Exposure of Sensitive Information to an Unauthorized Actor15 May 2415 May 24

Description

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.

Affected Products

ProductAffected VersionPatched Version
Artifactory SaaS< 7.85.07.85.0
Artifactory Self-Hosted< 7.84.77.84.7

How to Fix

  • Cloud Environments: JFrog Cloud environments are protected against this vulnerability with a deployed version containing the fix.
  • Self-Hosted Environments: To fix this issue, take the following action. Upgrade your version of Artifactory to one of the versions listed above.

Workarounds and Mitigations

No workarounds.

Acknowledgements

This issue was discovered and reported by the researcher Master Hackor via HackerOne.

CVE-2024-4142 - Improper Input Validation in Artifactory Token Creation Flow

Critical security vulnerability CVE-2024-4142 affecting JFrog Artifactory with improper input validation that could lead to privilege escalation.

CVE IDSeverityCWE / Weakness TypeDate PublishedDate Updated
CVE-2024-4142CriticalCWE-20 Improper Input Validation1 May 24

Description

An Improper input validation vulnerability was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system, an issue that could potentially lead to privilege escalation.

This issue can also be exploited in Artifactory platforms with anonymous access enabled.

Affected Products

ProductAffected VersionPatched Versions
Artifactory Self-Hosted

<7.55.17

<7.59.22

<7.63.21

<7.68.21

<7.71.21

<7.77.11

7.55.17

7.59.22

7.63.21

7.68.21

7.71.21

7.77.11

Artifactory Cloud<7.84.67.84.6

How to Fix

  • Cloud environments: No action is required for Cloud environments: the affected environments have already been protected.
  • Self-Hosted environments: Update to one of the provided patched/ fixed versions listed above.

To apply the security fix, you must upgrade your version of JFrog Artifactory to one of the remediating versions.

To download and install remediating versions, click here. Please ensure that you select the correct patch for your current installation from the Product Version drop-down list.

For further details on how to upgrade to any of the remediating versions from your current installation, please refer to the JFrog Artifactory Upgrade Guide.

Acknowledgements

This issue was discovered and reported by Matthias Kaiser of Apple Information Security.

CVE-2024-3505 - Proxy Configuration Accessible to Low-privilege Users

CVE IDSeverityCWE / Weakness TypeDate PublishedDate Updated
CVE-2024-350MediumCWE-200 Exposure of Sensitive Information to an Unauthorized Actor11 Apr 2411 Apr 24

Description

JFrog Artifactory Self-Hosted versions prior to 7.77.3 are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

Severity

Medium

Affected Products

ProductAffected VersionPatched Version
Artifactory Self-Hosted< 7.77.37.77.3

How to Fix

  • Cloud environments: Cloud environments are not affected by this issue.
  • Self-Hosted environments: To fix this issue, take the following action. Upgrade your version of Artifactory to one of the versions listed below.

Workarounds and Mitigations

None

Acknowledgements

This issue was discovered and reported by a JFrog customer.

CVE-2024-2247: JFrog Artifactory Cross-Site Scripting

CVE IDSeverityDate PublishedDate Updated
CVE-2024-2247High13 Mar 2413 Mar 24

Description

JFrog Artifactory prior to version 7.77.7, is vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.

Severity

High

Affected Products

ProductAffected VersionPatched Version
Artifactory Self-Hosted< = 7.77.67.77.7

How to Fix

  • Cloud Environments: JFrog cloud environments are protected. No action is required for cloud instances.
  • Self Hosted Environments: Update to version 7.77.7

Workarounds and Mitigations

Customers can block the import of the vulnerable script by the browser, using a WAF / reverse proxy rule that blocks requests to the following HTTP path: /ui/externals/import-map-overrides/dist/import-map-overrides.js

Weakness Type

CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Acknowledgements

Reported by CaTz.

We are here for your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2023-42661: JFrog Artifactory Improper Input Validation Leads to Arbitrary File Write

CVE IDSeverityDate PublishedDate Updated
CVE-2023-42661High7 Mar 247 Mar 24

Description

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.

Severity

High

CVSSv3.1 Base Score: 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

ProductAffected VersionPatched Version
Artifactory (7.x)Earlier than 7.76.2

7.76.2 or later (SaaS)

7.77.3 or later (On-prem)

Required Configuration for Exposure

This vulnerability affects all JFrog Artifactory deployments.

How to Fix

Cloud Environments: Affected Cloud environments have already been updated with a fixed version. No action is required for cloud instances.

Self Hosted Environments: To fix this issue, take the following action. Upgrade your version of Artifactory to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.77.3 or later (On-prem)

Workarounds and Mitigations

No workarounds

Weakness Type

CWE-20: Improper Input validation

Acknowledgements

This issue was discovered and reported by Matthias Kaiser from Apple Information Security.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2023-42509: JFrog Artifactory Sensitive Data Leakage in Repository Configuration Process

CVE IDSeverityDate PublishedDate Updated
CVE-2023-42509Medium7 Mar 247 Mar 24

Description

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

Severity

Medium

CVSSv3.1 Base Score: 6.6 AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)7.17.4 and later but prior to version 7.77.0
  • 7.77.0 and higher (SaaS)
  • 7.77.3 and higher (On-prem)

Required Configurations for Exposure

This vulnerability affects all JFrog Artifactory deployments.

How to Fix

Cloud Environments: Affected Cloud environments have already been upgraded with a fixed version. No action is required for cloud instances.

Self Hosted Environments: To fix this issue, the following action is required.

Upgrade your version of Artifactory to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.77.3 or newer (On-Prem)

Workarounds and Mitigations

No workarounds

Weakness Type

CWE-755: Improper Handling of Exceptional Conditions

Acknowledgements

This issue was discovered and reported by Matthias Kaiser from Apple Information Security.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2023-42662: Improper SSO Mechanism may lead to Exposure of Access Tokens

CVE IDSeverityDate PublishedDate Updated
CVE-2023-42662CRITICAL6 Mar 246 Mar 24

Description

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

Severity

CRITICAL

Affected Products

ProductAffected VersionsPatched Versions
Artifactory
  • 7.59.17 and lower
  • 7.63.17 and lower
  • 7.69.18 and lower
  • 7.71.7 and lower
  • 7.59.18 and higher
  • 7.63.18 and higher
  • 7.69.19 and higher
  • 7.71.8 and higher

How to Fix

Cloud Environments: Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self Hosted Environments: Update to one of a fixed version

Workarounds and Mitigations

Block access to the CLI token exchange API endpoint:
https://Artifactory-Host/access/api/v2/authentication/jfrog_client_login/token/*

Weakness Type

CWE-287: CWE-287 Improper Authentication

Acknowledgements

N/A

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2023-42508: JFrog Artifactory Improper Header Input Validation

CVE IDSeverityDate PublishedDate Updated
CVE-2023-42508MEDIUM10/04/202310/04/2023

Description

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

Severity: Medium

CVSSv3.1 Base Score: 6.5 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.66.0

7.66.0 (SaaS)

7.68.7 (On-prem)

Required Configuration for Exposure

This vulnerability affects all JFrog Artifactory deployments.

How to Fix

How to fix depends upon your environment, as follows:

  • Cloud Environments
  • Self Hosted Environments

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.68.7

Workarounds and Mitigations

No workarounds.

Weakness Type

CWE-20: Improper Input Validation.

Acknowledgements

This issue was discovered and reported by Iddo Eldor from Blindspot Security.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2022-0668: Artifactory Authentication Bypass

CVE IDSeverityDate PublishedDate Updated
CVE-2022-0668MEDIUM02/01/202302/01/2023

Description

JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.

Severity: Medium

CVSSv3 Score: 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.37.137.37.13
Artifactory (6.x)< 6.23.41Latest version of 6.23.x

Required Configuration for Exposure

This vulnerability affects all JFrog Artifactory deployments.

How to Fix

Cloud Enviornments: Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.37.13https://releases.jfrog.io

Exploitation Status

JFrog is not aware of publicly available exploits and malicious exploitation attempts.

Weakness Type

CWE-274: Improper Handling of Insufficient Privileges.

Acknowledgements

This issue was discovered and reported by Matthias Kaiser and Jonni Passki of Apple Information Security.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-45721: Cross-Site Script (XSS) on User REST API

CVE IDSeverityDate PublishedDate Updated
CVE-2021-45721MEDIUM07/05/20207/05/2022

Description

JFrog Artifactory prior to version 7.29.8 and 6.23.38is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint.

Severity: Medium

CVSSv3.1 Score: 6.1AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.29.87.29.8
Artifactory (6.x)< 6.23.386.23.38

Required Configuration

This vulnerability affects JFrog Artifactory deployments.

This issue requires an attacker to have authenticated access to JFrog Artifactory as Administrator

How to Fix

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.29.8 and abovehttps://releases.jfrog.io
Artifactory (6.x)6.23.38 and abovehttps://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE- 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Acknowledgements

This issue was discovered and reported by Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-46687: Sensitive data exposure on proxy endpoint for Project Admin

CVE IDSeverityDate PublishedDate Updated
CVE-2021-46687MEDIUM07/05/202207/05/2022

Description

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API.

Severity: Medium

CVSSv3.1 Score: 4.9AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.31.107.31.10
Artifactory (6.x)< 6.23.386.23.38

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This issue requires an attacker to have authenticated access to JFrog Artifactory as Project Administrator.

How to Fix

Cloud Enviornments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.31.10 and abovehttps://releases.jfrog.io
Artifactory (6.x)6.23.38 and abovehttps://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE- 359: Exposure of Private Personal Information to an Unauthorized Actor

Acknowledgements

This issue was discovered and reported by Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-23163: Cross-Site Request Forgery on REST using Basic Auth

CVE IDSeverityDate PublishedDate Updated
CVE-2021-23163LOW07/05/202207/05/2022

Description

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints.

Severity: LOW

CVSSv3.1 Score: 3.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.33.67.33.6
Artifactory (6.x)< 6.23.386.23.38

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This issue requires a user to enter their credentials in a www-authenticate negotiation, or have accessed some of the Artifactory REST APIs using basic credentials in the URL. (user:pass@artifactory-domain).

How to Fix

Cloud

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.33.6 and abovehttps://releases.jfrog.io
Artifactory (6.x)6.23.38 and abovehttps://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE-352: Cross-Site Request Forgery (CSRF)

Acknowledgements

This issue was discovered and reported by Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-41834: Artifactory Broken Access Control on Copy Artifact

CVE IDSeverityDate PublishedDate Updated
CVE-2021-41834MEDIUM18/5/202218/5/2022

Description

JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

Severity: Medium CVSSv3 Score: 5.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.28.07.28.0
Artifactory (6.x)< 6.23.386.23.38

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This vulnerability requires authenticated access to JFrog Artifactory and knowing a path of a repository or artifact that the user does not have access to.

How to Fix

Cloud

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.28.0https://releases.jfrog.io
Artifactory (6.x)6.23.38https://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE-284: Improper Access Control

Acknowledgements

Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-45730: Artifactory Broken Access Control on Repository Layouts Configuration

CVE IDSeverityDate PublishedDate Updated
CVE-2021-45730MEDIUM18/5/202218/5/2022

Description

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

Severity: MEDIUM

CVSSv3.1 Base Score:6.0CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.31.107.31.10

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This vulnerability requires authenticated access to JFrog Artifactory and Project Admin permissions.

How to Fix

Cloud

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your Artifactory version to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.31.10https://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE-284: Improper Access Control

Acknowledgements

Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-46270: Artifactory Project Admin Repository Name Disclosure

CVE IDSeverityDate PublishedDate Updated
CVE-2021-46270LOW03/02/202203/02/2022

Description

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin user is able to list all available repository names due to insufficient permission validation.

Severity: LOW

CVSSv3.1 Base Score:2.7AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.31.107.31.10

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This issue requires authenticated access to JFrog Artifactory and Project Admin permissions.

How to Fix

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your Artifactory version to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.31.10https://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE-284: Improper Access Control

Acknowledgements

Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-45074: Artifactory Broken Access Control on Delete OAuth Tokens

CVE IDSeverityDate PublishedDate Updated
CVE-2021-45074MEDIUM03/02/202203/02/2022

Description

JFrog Artifactory prior to 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known usersOAuthtoken, which will force re-authentication on an active session or in the next UI session.

Severity: MEDIUM

CVSSv3.1 Base Score:4.3AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.29.37.29.3
Artifactory (6.x)< 6.23.386.23.38

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This vulnerability requires authenticated access to JFrog Artifactory and guessing the username of another user, as well as an OAuth token.

How to Fix

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your Artifactory version to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)7.29.3https://releases.jfrog.io
Artifactory (6.x)6.23.38https://releases.jfrog.io

Workarounds and Mitigations

There aren’t any suggested workarounds to this issue besides upgrading to a fixed version.

Weakness Type

CWE-284: Improper Access Control

Acknowledgements

Maxime Escourbiac and Maxence Schmitt at Michelin CERT.

We Are Here For Your Questions (JFrog Support Team)****

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2021-3860: Artifactory Low Privileged Blind SQL Injection

CVE IDSeverityDate PublishedDate Updated
CVE-2021-3860HIGH12/15/202112/15/2021

Description

JFrog Artifactory prior to 7.25.4 (Enterprise+ subscriptions only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

Severity: High

CVSSv3 Score: 8.8 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.25.47.24.7, 7.23.8, 7.21.14, 7.19.12, 7.18.11, 7.17.14, 7.12.10, 7.11.8
Artifactory (6.x)< 6.23.30Latest version of 6.23.x

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory and JFrog edge deployments with Enterprise+ subscriptions only.

This issue requires an attacker to have authenticated access to JFrog Artifactory.

📘

Note

If your environment permits anonymous access, there is a higher potential of exposure to the vulnerability.

How to Fix

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your version of Artifactory or Edge to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)Latesthttps://releases.jfrog.io
Artifactory (7.x)7.24.7https://releases.jfrog.io
Artifactory (7.x)7.23.8https://releases.jfrog.io
Artifactory (7.x)7.21.14https://releases.jfrog.io
Artifactory (7.x)7.19.12https://releases.jfrog.io
Artifactory (7.x)7.18.11https://releases.jfrog.io
Artifactory (7.x)7.17.14https://releases.jfrog.io
Artifactory (7.x)7.12.10https://releases.jfrog.io
Artifactory (7.x)7.11.8https://releases.jfrog.io
Artifactory (6.x)Latest 6.23.x versionhttps://releases.jfrog.io

Workarounds and Mitigations

You can mitigate the impact of this issue by following best practices and disabling anonymous access to the JFrog Platform. Please review the best practices for disabling anonymous access in the JFrog knowledge base.

📘

Note

Anonymous Access is disabled by default for new Artifactory and Edge installations starting from versions 6.12.0 and 7.0.0.

Exploitation Status

JFrog is not aware of publicly available exploits and malicious exploitation attempts.

Weakness Type

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').

Acknowledgements

This issue was discovered and reported by a JFrog customer.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.

CVE-2022-0573: Artifactory Vulnerable to Deserialization of Untrusted Data

CVE IDSeverityDate PublishedDate Updated
CVE-2022-0573HIGH12/5/2022

Description

JFrog Artifactory prior to 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.

Severity: HIGH

CVSSv3.1 Base Score:8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

ProductAffected VersionsPatched Versions
Artifactory (7.x)< 7.36.1
  • 7.17.16
  • 7.18.12
  • 7.19.13
  • 7.21.25
  • 7.25.9
  • 7.27.15
  • 7.29.10
  • 7.31.16
  • 7.33.12
  • 7.34.4
  • 7.35.1
  • 7.36.1
Artifactory (6.x)< 6.23.416.23.41

Required Configuration for Exposure

This vulnerability affects JFrog Artifactory deployments.

This issue requires an attacker to have authenticated access to JFrog Artifactory.

If your environment permits anonymous access, there is a higher potential of exposure to the vulnerability.

How to Fix

Cloud Environments

Affected Cloud environments have already been fortified with a fixed version. No action is required for cloud instances.

Self-Hosted Environments

To fix this issue, there is required action.

Upgrade your Artifactory version to one of the versions listed below:

ProductVersionLink
Artifactory (7.x)latesthttps://releases.jfrog.io
Artifactory (7.x)7.17.16https://releases.jfrog.io
Artifactory (7.x)7.18.12https://releases.jfrog.io
Artifactory (7.x)7.19.13https://releases.jfrog.io
Artifactory (7.x)7.21.25https://releases.jfrog.io
Artifactory (7.x)7.25.9https://releases.jfrog.io
Artifactory (7.x)7.27.15https://releases.jfrog.io
Artifactory (7.x)7.29.10https://releases.jfrog.io
Artifactory (7.x)7.31.16https://releases.jfrog.io
Artifactory (7.x)7.33.12https://releases.jfrog.io
Artifactory (7.x)7.34.3https://releases.jfrog.io
Artifactory (7.x)7.35.1https://releases.jfrog.io
Artifactory (7.x)7.36.1https://releases.jfrog.io
Artifactory (6.x)Latest 6.23.x versionhttps://releases.jfrog.io

Workarounds and Mitigations

You can mitigate the impact of this issue by following best practices and disabling anonymous access to the JFrog Platform. Please review the best practices for disabling anonymous access in the JFrog Knowledge Base.

📘

Note

Anonymous Access is disabled by default for new Artifactory and Edge installations starting from versions 6.12.0 and 7.0.0.

Weakness Type

CWE-502: Deserialization of Untrusted Data

Acknowledgements

This issue was discovered and reported by Matthias Kaiser and Jonni Passki of Apple Information Security.

We Are Here For Your Questions (JFrog Support Team)

If you have questions or concerns regarding this advisory, please raise a support request at JFrog support portal.


Did this page help you?