Jfrog
Jfrog Artifactory: vulnerabilidades y CVE
Jfrog Artifactory tiene 76 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 9 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE76
Últimos 12 meses41
Críticas9
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42016 | Alta (8.8) | 8.6% | ⚠ Explotación activa | 27 jul 2026 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. |
| CVE-2026-42018 | Alta (7.5) | 9.8% | ⚠ Explotación activa | 12 ago 2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |
| CVE-2026-82329 | Crítica (9.8) | 14% | ⚠ Explotación activa | 28 ago 2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
| CVE-2026-66384 | Media (5.3) | 0.66% | ⚠ Explotación activa | 12 ago 2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82329 | Crítica (9.8) | 14% | ⚠ Explotación activa | 28 ago 2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
| CVE-2026-70550 | Media (6.5) | 0.35% | — | 25 ago 2026 | An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The… |
| CVE-2026-70548 | Baja (3.5) | 0.29% | — | 25 ago 2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. |
| CVE-2026-69106 | Alta (8.8) | 0.52% | — | 12 ago 2026 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. |
| CVE-2026-42018 | Alta (7.5) | 9.8% | ⚠ Explotación activa | 12 ago 2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |
| CVE-2026-70547 | Media (4.3) | 0.28% | — | 12 ago 2026 | An authenticated user without repository read permission may access package metadata under specific conditions. |
| CVE-2026-69107 | Media (5.9) | 0.41% | — | 12 ago 2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. |
| CVE-2026-69105 | Alta (8.1) | 0.20% | — | 12 ago 2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. |
| CVE-2026-68759 | Alta (7.2) | 0.33% | — | 12 ago 2026 | A holder of a valid integration credential may impersonate other users under specific conditions. |
| CVE-2026-68758 | Media (6.5) | 0.35% | — | 12 ago 2026 | A low-privileged authenticated user may access restricted support information under specific conditions. |
| CVE-2026-66384 | Media (5.3) | 0.66% | ⚠ Explotación activa | 12 ago 2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. |
| CVE-2026-66016 | Media (6.7) | 0.12% | — | 12 ago 2026 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. |
| CVE-2026-68760 | Media (5.3) | 0.46% | — | 12 ago 2026 | An unauthenticated user may bypass authentication under specific cache conditions. |
| CVE-2026-68757 | Alta (7.5) | 0.27% | — | 12 ago 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. |
| CVE-2026-68756 | Media (6.6) | 0.47% | — | 12 ago 2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. |
| CVE-2026-68755 | Media (4.3) | 0.26% | — | 12 ago 2026 | A bundle writer may create misleading release promotion information under specific conditions. |
| CVE-2026-68754 | Media (6.5) | 0.31% | — | 12 ago 2026 | A repository publisher without delete permission may modify protected package content under specific conditions. |
| CVE-2026-68753 | Media (5.3) | 0.31% | — | 12 ago 2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. |
| CVE-2026-68752 | Alta (7.2) | 0.49% | — | 12 ago 2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| CVE-2026-66382 | Media (4.3) | 0.35% | — | 12 ago 2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. |
| CVE-2026-66381 | Media (5.3) | 0.39% | — | 12 ago 2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. |
| CVE-2026-66380 | Media (4.3) | 0.30% | — | 12 ago 2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. |
| CVE-2026-66379 | Media (4.3) | 0.30% | — | 12 ago 2026 | An authenticated user may view private Puppet module metadata without repository read access. |
| CVE-2026-66378 | Media (4.3) | 0.30% | — | 12 ago 2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| CVE-2026-66377 | Media (5.3) | 0.36% | — | 12 ago 2026 | An unauthenticated user may access restricted repository information under specific conditions. |
| CVE-2026-66376 | Media (5.4) | 0.22% | — | 12 ago 2026 | Credentials for a deleted user may remain valid for a short period under specific conditions. |
| CVE-2026-66375 | Alta (8.1) | 0.40% | — | 12 ago 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. |
| CVE-2026-66018 | Media (6.5) | 0.39% | — | 27 jul 2026 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a… |
| CVE-2026-66015 | Alta (7.2) | 0.57% | — | 27 jul 2026 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access. |
| CVE-2026-66014 | Alta (8.8) | 0.64% | — | 27 jul 2026 | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.