artifactory vulnerabilities
CVEs whose affected-version data names the artifactory package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
CVE-2026-42018High· 7.5CISA KEVPoCAnonymous user token generation exposure in JFrog Artifactory
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-69106High· 8.8A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-70547Medium· 4.3An authenticated user without repository read permission may access package metadata under specific conditions.
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69107Medium· 5.9An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-69105High· 8.1An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-66016Medium· 6.7Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-66014High· 8.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-42016High· 8.1CISA KEVPoCIncorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.