Vulnerabilities
Vulnerable Software
Jfrog:  >> Artifactory  >> 2.2.2  Security Vulnerabilities
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-08-12
CVE-2026-42018
Known exploited
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS Score
7.5
EPSS Score
0.11
Published
2026-08-12
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVSS Score
5.9
EPSS Score
0.003
Published
2026-08-12
A holder of a valid integration credential may impersonate other users under specific conditions.
CVSS Score
7.2
EPSS Score
0.002
Published
2026-08-12
A low-privileged authenticated user may access restricted support information under specific conditions.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-08-12
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-08-12
CVE-2026-66384
Known exploited
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVSS Score
5.3
EPSS Score
0.006
Published
2026-08-12
A repository publisher without delete permission may modify protected package content under specific conditions.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-08-12
A bundle writer may create misleading release promotion information under specific conditions.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVSS Score
6.6
EPSS Score
0.003
Published
2026-08-12


Contact Us

Shodan ® - All rights reserved