cbcvebase.
CVE-2026-70550
published 2026-08-25

CVE-2026-70550: An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package…

PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.21%
11.1th percentile
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.

Affected

2 ranges
VendorProductVersion rangeFixed in
jfrogartifactory>= 7.146.0 < 7.146.297.146.29
jfrogartifactory>= 7.161.0 < 7.161.197.161.19
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.