vendor

jfrog

8 thingsrelated by NVD
Severity
Exploited

Its products

artifactory 8

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-70547
Severity medium
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-69107
Severity medium
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted…
CVE-2026-69106
Severity high
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact…
CVE-2026-69105
Severity high
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly…
CVE-2026-66016
Severity medium
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an…
CVE-2026-66014
Severity high
JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-42018
Severity high Exploited yes
JFrog Artifactory Incorrect Authorization Vulnerability
CVE-2026-42016
Severity high Exploited yes