Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  Security Vulnerabilities
CVE-2026-82329
Known exploited
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
CVSS Score
9.8
EPSS Score
0.077
Published
2026-08-28
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-08-12
CVE-2026-42018
Known exploited
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS Score
7.5
EPSS Score
0.11
Published
2026-08-12
An authenticated user without repository read permission may access package metadata under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVSS Score
8.1
EPSS Score
0.001
Published
2026-08-12
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVSS Score
5.9
EPSS Score
0.003
Published
2026-08-12
A holder of a valid integration credential may impersonate other users under specific conditions.
CVSS Score
7.2
EPSS Score
0.002
Published
2026-08-12
A low-privileged authenticated user may access restricted support information under specific conditions.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-08-12
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-08-12
CVE-2026-66384
Known exploited
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVSS Score
5.3
EPSS Score
0.006
Published
2026-08-12


Contact Us

Shodan ® - All rights reserved