VulnSea

artifactory vulnerabilities

CVEs whose affected-version data names the artifactory package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Abyssaljfrog · artifactoryEPSS 11%via CVEORG
CVE-2026-69106High· 8.8
1mo ago

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

Twilightjfrog · artifactoryEPSS 0.36%via NVD
CVE-2026-70547Medium· 4.3
1mo ago

An authenticated user without repository read permission may access package metadata under specific conditions.

An authenticated user without repository read permission may access package metadata under specific conditions.

Sunlitjfrog · artifactoryEPSS 0.20%via NVD
CVE-2026-69107Medium· 5.9
1mo ago

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

Sunlitjfrog · artifactoryEPSS 0.32%via NVD
CVE-2026-69105High· 8.1
1mo ago

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

Twilightjfrog · artifactoryEPSS 0.13%via NVD
CVE-2026-66016Medium· 6.7
1mo ago

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

Sunlitjfrog · artifactoryEPSS 0.09%via NVD
CVE-2026-66014High· 8.8
1mo ago

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Twilightjfrog · artifactoryEPSS 0.64%via NVD
CVE-2026-42016High· 8.1CISA KEVPoC
1mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Abyssaljfrog · artifactoryEPSS 9.1%via CVEORG
artifactory vulnerabilities (CVEs) · VulnSea