Search Results (80 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-82329 1 Jfrog 1 Artifactory 2026-09-03 9.8 Critical
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVE-2026-66375 1 Jfrog 1 Artifactory 2026-09-02 8.1 High
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
CVE-2026-66376 1 Jfrog 1 Artifactory 2026-09-02 4.2 Medium
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66377 1 Jfrog 1 Artifactory 2026-09-02 5.3 Medium
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66378 1 Jfrog 1 Artifactory 2026-09-02 4.3 Medium
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66379 1 Jfrog 1 Artifactory 2026-09-02 4.3 Medium
An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66380 1 Jfrog 1 Artifactory 2026-09-02 4.3 Medium
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-66381 1 Jfrog 1 Artifactory 2026-09-02 5.3 Medium
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVE-2026-66382 1 Jfrog 1 Artifactory 2026-09-02 4.3 Medium
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-68752 1 Jfrog 1 Artifactory 2026-09-02 7.2 High
A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-68753 1 Jfrog 1 Artifactory 2026-09-02 5.3 Medium
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-68754 1 Jfrog 1 Artifactory 2026-09-02 6.5 Medium
A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68755 1 Jfrog 1 Artifactory 2026-09-02 4.3 Medium
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68756 1 Jfrog 1 Artifactory 2026-09-02 6.6 Medium
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68757 1 Jfrog 1 Artifactory 2026-09-02 7.5 High
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68760 1 Jfrog 1 Artifactory 2026-09-02 5.3 Medium
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68758 1 Jfrog 1 Artifactory 2026-09-02 6.5 Medium
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-68759 1 Jfrog 1 Artifactory 2026-09-02 7.2 High
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-66384 1 Jfrog 1 Artifactory 2026-08-27 5.3 Medium
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-70551 1 Jfrog 1 Artifactory 2026-08-26 8.5 High
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.