Jfrog: community verdicts
13 notable / known-exploited Jfrog CVEs the community has triaged.
- CVE-2026-65921HIGH 8.8Real · low riskEPSS 0%
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
- CVE-2026-66015HIGH 7.2Real · low riskEPSS 0%
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
- CVE-2026-66014HIGH 8.8Real · low riskEPSS 0%
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
- CVE-2026-65617HIGH 8.8Real · low riskEPSS 0%
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- CVE-2026-42017HIGH 8.8Real · low riskEPSS 0%
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
- CVE-2026-66018MED 6.5EPSS 0%
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
- CVE-2026-65924MED 6.5EPSS 0%
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
- CVE-2026-42016HIGH 8.1Real · low riskEPSS 0%
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- CVE-2026-65925MED 6.5EPSS 0%
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
- CVE-2026-65618MED 6.5EPSS 0%
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
- CVE-2026-65922HIGH 7.1Real · low riskEPSS 0%
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
- CVE-2026-65923MED 6.8EPSS 0%
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
- CVE-2026-65616HIGH 8.8Real · low riskEPSS 0%
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.