CVE-2026-66014High· 8.8▾ TwilightJFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
artifactory < 7.111.18artifactory >= 7.117.0, < 7.117.25artifactory >= 7.125.0, < 7.125.18artifactory >= 7.133.0, < 7.133.27artifactory >= 7.146.0, < 7.146.34artifactory >= 7.161.0, < 7.161.15Upgrade past the affected range:
artifactory 7.161.15Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory
CVE-2026-42016High· 8.1Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
CVE-2026-69106High· 8.8A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-69107Medium· 5.9An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-70547Medium· 4.3An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69105High· 8.1An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.