← Back to CVE search

CVE-2026-70550

JFrog Artifactory

Description

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.

CVSS 6.5EPSS 0.209%Risk 0.66
View source
Published
2026-08-25 16:17:08
Affected versions
unknown
Type
Web application
Last modified
2026-08-26 20:17:58
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N