« Volver al listado

Jfrog

Jfrog Artifactory: vulnerabilidades y CVE

Jfrog Artifactory tiene 76 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 9 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE76
Últimos 12 meses41
Críticas9
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42016Alta (8.8)8.6%⚠ Explotación activa27 jul 2026
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2026-42018Alta (7.5)9.8%⚠ Explotación activa12 ago 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-82329Crítica (9.8)14%⚠ Explotación activa28 ago 2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVE-2026-66384Media (5.3)0.66%⚠ Explotación activa12 ago 2026
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-82329Crítica (9.8)14%⚠ Explotación activa28 ago 2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVE-2026-70550Media (6.5)0.35%—25 ago 2026
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The…
CVE-2026-70548Baja (3.5)0.29%—25 ago 2026
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
CVE-2026-69106Alta (8.8)0.52%—12 ago 2026
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-42018Alta (7.5)9.8%⚠ Explotación activa12 ago 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-70547Media (4.3)0.28%—12 ago 2026
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69107Media (5.9)0.41%—12 ago 2026
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-69105Alta (8.1)0.20%—12 ago 2026
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-68759Alta (7.2)0.33%—12 ago 2026
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-68758Media (6.5)0.35%—12 ago 2026
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-66384Media (5.3)0.66%⚠ Explotación activa12 ago 2026
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-66016Media (6.7)0.12%—12 ago 2026
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-68760Media (5.3)0.46%—12 ago 2026
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68757Alta (7.5)0.27%—12 ago 2026
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68756Media (6.6)0.47%—12 ago 2026
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68755Media (4.3)0.26%—12 ago 2026
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68754Media (6.5)0.31%—12 ago 2026
A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68753Media (5.3)0.31%—12 ago 2026
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-68752Alta (7.2)0.49%—12 ago 2026
A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-66382Media (4.3)0.35%—12 ago 2026
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381Media (5.3)0.39%—12 ago 2026
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVE-2026-66380Media (4.3)0.30%—12 ago 2026
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-66379Media (4.3)0.30%—12 ago 2026
An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378Media (4.3)0.30%—12 ago 2026
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377Media (5.3)0.36%—12 ago 2026
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66376Media (5.4)0.22%—12 ago 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66375Alta (8.1)0.40%—12 ago 2026
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVE-2026-66018Media (6.5)0.39%—27 jul 2026
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a…
CVE-2026-66015Alta (7.2)0.57%—27 jul 2026
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVE-2026-66014Alta (8.8)0.64%—27 jul 2026
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts3
  2. T1190 Exploit Public-Facing Application2
  3. T1210 Exploitation of Remote Services2
  4. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Jfrog