Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  Security Vulnerabilities
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
CVSS Score
6.5
EPSS Score
0.004
Published
2026-07-27
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
CVSS Score
6.5
EPSS Score
0.004
Published
2026-07-27
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-07-27
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVSS Score
7.2
EPSS Score
0.006
Published
2026-07-27
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
CVSS Score
8.8
EPSS Score
0.002
Published
2026-07-27
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-07-27
CVE-2026-42016
Known exploited
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS Score
8.1
EPSS Score
0.091
Published
2026-07-27
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-07-27
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVSS Score
4.3
EPSS Score
0.004
Published
2024-04-15
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
CVSS Score
8.8
EPSS Score
0.005
Published
2024-03-13


Contact Us

Shodan ® - All rights reserved