jfrog
38 known vulnerabilities affecting jfrog products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-82329 | Act now | 7.7% | 9.8 | ● | JFrog Artifactory contains an authentication weakness that, under default config… |
| CVE-2026-42018 | Act now | 0.9% | 7.5 | ● | JFrog Artifactory could return an internal anonymous-user token to an unauthenti… |
| CVE-2026-42016 | Act now | 0.9% | 8.1 | ● | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri… |
| CVE-2026-66384 | Act now | 0.6% | 5.3 | ● | An authenticated user may write data outside the intended Docker cache path unde… |
| CVE-2026-65617 | Medium | 0.7% | 8.8 | A deserialization weakness in JFrog Artifactory package handling could allow a l… | |
| CVE-2026-66015 | Medium | 0.6% | 7.2 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exp… | |
| CVE-2026-65921 | Medium | 0.6% | 8.8 | A path validation weakness in archive extraction/write handling allows entries w… | |
| CVE-2026-66014 | Medium | 0.6% | 8.8 | JFrog Artifactory contains an authentication handling weakness in internal reque… | |
| CVE-2026-69106 | Medium | 0.4% | 8.8 | A low-privileged user may poison cached artifact metadata under specific conditi… | |
| CVE-2026-68752 | Medium | 0.3% | 7.2 | A Project Resource Manager may gain broader administrative privileges under spec… | |
| CVE-2026-42017 | Medium | 0.3% | 8.8 | An event-handling weakness in JFrog Artifactory could expose privileged authoriz… | |
| CVE-2026-66375 | Medium | 0.3% | 8.1 | A low-privilege authenticated user may permanently remove protected internal met… | |
| CVE-2026-65922 | Medium | 0.3% | 7.1 | An authorization weakness in JFrog Artifactory internal metadata handling could … | |
| CVE-2026-68759 | Medium | 0.2% | 7.2 | A holder of a valid integration credential may impersonate other users under spe… | |
| CVE-2026-65616 | Medium | 0.2% | 8.8 | Incorrect authorization validation in refresh token signature allows non-admin u… | |
| CVE-2026-68757 | Medium | 0.2% | 7.5 | A user with access to a valid SAML response may impersonate another user under s… | |
| CVE-2026-69105 | Medium | 0.1% | 8.1 | An unauthenticated attacker may cause untrusted package content to be cached und… | |
| CVE-2026-66018 | Low | 0.4% | 6.5 | Build readers can access another repository's environment properties. A caller w… | |
| CVE-2026-65924 | Low | 0.4% | 6.5 | JFrog Artifactory support for Terraform remote repositories was found to be susc… | |
| CVE-2026-68760 | Low | 0.4% | 5.3 | An unauthenticated user may bypass authentication under specific cache condition… | |
| CVE-2026-65925 | Low | 0.4% | 6.5 | A user with JFrog Artifactory Cargo remote repository read access could make Art… | |
| CVE-2026-65923 | Low | 0.3% | 6.8 | A URL validation weakness in JFrog Artifactory Ansible repository handling could… | |
| CVE-2026-68756 | Low | 0.3% | 6.6 | A party with write access to stored session data may affect JFrog Artifactory un… | |
| CVE-2026-69107 | Low | 0.3% | 5.9 | An unauthenticated user may access restricted artifacts in JFrog Artifactory und… | |
| CVE-2026-66381 | Low | 0.3% | 5.3 | A repository reader with cache-deploy permission may access content outside a co… | |
| CVE-2026-66377 | Low | 0.3% | 5.3 | An unauthenticated user may access restricted repository information under speci… | |
| CVE-2026-66382 | Low | 0.3% | 4.3 | An authenticated user may write files outside the intended Artifactory work dire… | |
| CVE-2026-68758 | Low | 0.3% | 6.5 | A low-privileged authenticated user may access restricted support information un… | |
| CVE-2026-68753 | Low | 0.2% | 5.3 | An unauthenticated user may access restricted Artifactory content when a credent… | |
| CVE-2026-68754 | Low | 0.2% | 6.5 | A repository publisher without delete permission may modify protected package co… | |
| CVE-2026-66378 | Low | 0.2% | 4.3 | An authenticated user without repository read permission may access private NuGe… | |
| CVE-2026-66379 | Low | 0.2% | 4.3 | An authenticated user may view private Puppet module metadata without repository… | |
| CVE-2026-66380 | Low | 0.2% | 4.3 | An authenticated user without repository read permission may access private OCI … | |
| CVE-2026-65618 | Low | 0.2% | 6.5 | Improper URL validation when handling specific URLs, allows an attacker, under c… | |
| CVE-2026-70547 | Low | 0.2% | 4.3 | An authenticated user without repository read permission may access package meta… | |
| CVE-2026-68755 | Low | 0.2% | 4.3 | A bundle writer may create misleading release promotion information under specif… | |
| CVE-2026-66376 | Low | 0.2% | 4.2 | Credentials for a deleted user may remain valid for a short period under specifi… | |
| CVE-2026-66016 | Low | 0.1% | 6.7 | Under specific self-hosted Helm configurations, generated TLS private keys may b… |