JFrog Artifactory
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in JFrog Artifactory.
Known Exploited JFrog Artifactory Vulnerabilities
The following JFrog Artifactory vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| JFrog Artifactory Improper Authentication Vulnerability |
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. CVE-2026-82329 |
September 2, 2026 |
| JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability |
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. CVE-2026-66384 |
August 27, 2026 |
By the Year
In 2026 there have been 44 vulnerabilities in JFrog Artifactory with an average score of 6.5 out of ten. Artifactory did not have any published security vulnerabilities last year. That is, 44 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 44 | 6.50 |
| 2025 | 0 | 0.00 |
| 2024 | 7 | 6.64 |
| 2023 | 2 | 8.15 |
| 2022 | 8 | 6.01 |
| 2021 | 1 | 8.80 |
| 2020 | 5 | 7.93 |
| 2019 | 7 | 6.17 |
| 2018 | 2 | 8.00 |
It may take a day or so for new Artifactory vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JFrog Artifactory Security Vulnerabilities
Auth Bypass in JFrog Artifactory Allows Admin Privileges
CVE-2026-82329
9.8 - Critical
- August 28, 2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
authentification
Auth Bypass in JFrog Artifactory Composer Repo: Unauthorized Metadata Read
CVE-2026-70550
6.5 - Medium
- August 25, 2026
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
AuthZ
CVE-2026-70548: Remote Code Exec via Artifactory External Dep to CocoaPods
CVE-2026-70548
3.5 - Low
- August 25, 2026
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
SSRF
JFrog Artifactory Authenticated Repo Migration Priv Escalation
CVE-2026-69104
7.6 - High
- August 25, 2026
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
AuthZ
JFrog Artifactory VCS Origin Manipulation via Readable Remote Repo
CVE-2026-70551
8.5 - High
- August 25, 2026
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
SSRF
Low-Privileged User Can Poison Cached Artifact Metadata JFrog Artifactory
CVE-2026-69106
8.8 - High
- August 12, 2026
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
Improper Input Validation
Artifactory Internal Token Exposure with Disabled Anon Access
CVE-2026-42018
7.5 - High
- August 12, 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
authentification
Unauth Access to Restricted Artifacts in JFrog Artifactory (CVE-2026-69107)
CVE-2026-69107
5.9 - Medium
- August 12, 2026
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
AuthZ
Unauthenticated Cache Injection in JFrog Artifactory
CVE-2026-69105
8.1 - High
- August 12, 2026
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
Insufficient Verification of Data Authenticity
JFrog Artifactory Authenticated Package Metadata Leak
CVE-2026-70547
4.3 - Medium
- August 12, 2026
An authenticated user without repository read permission may access package metadata under specific conditions.
AuthZ
Helm TLS Private Key Exposure in Rendered Manifests
CVE-2026-66016
6.7 - Medium
- August 12, 2026
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
Cleartext Storage of Sensitive Information
User Impersonation via Valid Integration Credential (JFrog Artifactory)
CVE-2026-68759
7.2 - High
- August 12, 2026
A holder of a valid integration credential may impersonate other users under specific conditions.
Improper Verification of Cryptographic Signature
Jfrog Artifactory: Release Bundle Name Disclosure via Anonymous/Low-Priv Auth
CVE-2026-65926
3.1 - Low
- August 12, 2026
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
AuthZ
Auth Write Outside Docker Cache Path in JFrog Artifactory
CVE-2026-66384
5.3 - Medium
- August 12, 2026
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Directory traversal
Low-Privileged Auth User Access Restricted Support Info in JFrog Artifactory
CVE-2026-68758
6.5 - Medium
- August 12, 2026
A low-privileged authenticated user may access restricted support information under specific conditions.
AuthZ
Low-Privileged User Can Delete Metadata in JFrog Artifactory
CVE-2026-66375
8.1 - High
- August 12, 2026
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
AuthZ
SAML Response Impersonation in JFrog Artifactory
CVE-2026-68757
7.5 - High
- August 12, 2026
A user with access to a valid SAML response may impersonate another user under specific conditions.
Improper Verification of Cryptographic Signature
JFrog Artifactory Session Data Write Access Exploit
CVE-2026-68756
6.6 - Medium
- August 12, 2026
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
Marshaling, Unmarshaling
Artifactory Auth Write Outside Intended Dir
CVE-2026-66382
4.3 - Medium
- August 12, 2026
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
Directory traversal
JFrog Artifactory Path Traversal via cache-deploy perm
CVE-2026-66381
5.3 - Medium
- August 12, 2026
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
Directory traversal
Auth Bypass via Cache Conditions in JFrog Artifactory
CVE-2026-68760
5.3 - Medium
- August 12, 2026
An unauthenticated user may bypass authentication under specific cache conditions.
authentification
Authenticated Puppet module metadata exposure in JFrog Artifactory
CVE-2026-66379
4.3 - Medium
- August 12, 2026
An authenticated user may view private Puppet module metadata without repository read access.
AuthZ
NuGet Metadata Leak in JFrog Artifactory
CVE-2026-66378
4.3 - Medium
- August 12, 2026
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
AuthZ
Unauthenticated Repository Info Leak in JFrog Artifactory
CVE-2026-66377
5.3 - Medium
- August 12, 2026
An unauthenticated user may access restricted repository information under specific conditions.
AuthZ
Misleading release promotion via bundle writer in JFrog Artifactory
CVE-2026-68755
4.3 - Medium
- August 12, 2026
A bundle writer may create misleading release promotion information under specific conditions.
AuthZ
Unauth. Access to Private OCI Referrer Metadata in JFrog Artifactory
CVE-2026-66380
4.3 - Medium
- August 12, 2026
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
AuthZ
Privilege Escalation: Publisher Modifies Protected Packages in Artifactory
CVE-2026-68754
6.5 - Medium
- August 12, 2026
A repository publisher without delete permission may modify protected package content under specific conditions.
AuthZ
Unauth. access to restricted Artifactory content via credentialed remote repo
CVE-2026-68753
5.3 - Medium
- August 12, 2026
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
AuthZ
JFrog Artifactory: Deleted User Credentials Remain Valid
CVE-2026-66376
4.2 - Medium
- August 12, 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
Insufficient Session Expiration
Privilege Escalation via PRM in JFrog Artifactory
CVE-2026-68752
7.2 - High
- August 12, 2026
A Project Resource Manager may gain broader administrative privileges under specific conditions.
Improper Privilege Management
Auth Weakness in JFrog Artifactory Metadata Handling
CVE-2026-65922
7.1 - High
- July 27, 2026
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
AuthZ
Artifactory Ansible Repo URL Validation Flaw Enabling SSRF
CVE-2026-65923
6.8 - Medium
- July 27, 2026
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
SSRF
JFrog Artifactory Deserialization Flaw Allows Low-Priv Confid&IA
CVE-2026-65617
8.8 - High
- July 27, 2026
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
Marshaling, Unmarshaling
Artifactory Terraform Remote Repo SSRF (CVE-2026-65924)
CVE-2026-65924
6.5 - Medium
- July 27, 2026
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
SSRF
JFrog Artifactory Cargo: Remote URL Request via Read Access
CVE-2026-65925
6.5 - Medium
- July 27, 2026
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
SSRF
Non-Admin Users Exploit JFrog Artifactory Refresh Token for Sig Admin Token
CVE-2026-65616
8.8 - High
- July 27, 2026
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
Improper Verification of Cryptographic Signature
JFrog Platform PrivEsc via Admin-Provoked Auth
CVE-2026-66015
7.2 - High
- July 27, 2026
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
Improper Privilege Management
CVE-2026-65618 Artifactory URL Validation Exposes Internal Services
CVE-2026-65618
6.5 - Medium
- July 27, 2026
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
SSRF
JFrog Build Readers Access Protected Build Env Secrets
CVE-2026-66018
6.5 - Medium
- July 27, 2026
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Information Disclosure
Artifactory Auth Handling Weakness Enabling Privilege Escalation
CVE-2026-66014
8.8 - High
- July 27, 2026
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
authentification
Path Traversal in JFrog Artifactory Archive Extraction
CVE-2026-65921
8.8 - High
- July 27, 2026
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
Directory traversal
Event-Handling Weakness Exposes Priv Auth Data in JFrog Artifactory
CVE-2026-42017
8.8 - High
- July 27, 2026
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
Information Disclosure
Privilege Escalation in JFrog Artifactory <7.133.11 (Token Check)
CVE-2026-42016
8.1 - High
- July 27, 2026
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the tokens scope.
AuthZ
Artifactory Workers XSS Vulnerability 7.94.0-7.117.9
CVE-2025-14830
4.9 - Medium
- January 04, 2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
XSS
JFrog Artifactory Cache Poisoning via Improper Input Validation (<=7.90.6)
CVE-2024-6915
- August 05, 2024
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.
Improper Input Validation
Artifactory Privilege Escalation via Improper Input Validation (CVE-2024-4142)
CVE-2024-4142
- May 01, 2024
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
Improper Input Validation
JFrog Artifactory Self-Hosted Sensitive Info Disclosure (<7.77.3)
CVE-2024-3505
4.3 - Medium
- April 15, 2024
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
Information Disclosure
Artifactory DOMXSS via Import Override (<7.77.7 or <7.82.1)
CVE-2024-2247
6.1 - Medium
- March 13, 2024
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
XSS
Sensitive Data Leak in JFrog Artifactory 7.17.4<7.77 via Exception Handling
CVE-2023-42509
7.5 - High
- March 07, 2024
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
JFrog Artifactory <7.76.2: Arbitrary File Write via Authenticated Requests
CVE-2023-42661
8.8 - High
- March 07, 2024
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
Improper Input Validation
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for JFrog Artifactory or by JFrog? Click the Watch button to subscribe.