Jfrog: community verdicts
4 notable / known-exploited Jfrog CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Jfrog CVE, see NVD ↗.
- CVE-2026-82329CRIT 9.8KEVEPSS 8%
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
- CVE-2026-42018HIGH 7.5KEVEPSS 1%
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- CVE-2026-42016HIGH 8.1KEVEPSS 1%
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- CVE-2026-66384MED 5.3KEVEPSS 1%
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.