Known Vulnerabilities for products from Jfrog
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jfrog".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82329 json | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacke... | Not Provided | 2026-08-28 | 2026-09-03 |
| CVE-2026-70550 json | Not Provided | 2026-08-25 | 2026-08-26 | |
| CVE-2026-70548 json | Not Provided | 2026-08-25 | 2026-08-26 | |
| CVE-2026-69107 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-68760 json | An unauthenticated user may bypass authentication under specific cache conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68759 json | A holder of a valid integration credential may impersonate other users under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68758 json | A low-privileged authenticated user may access restricted support information under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68757 json | A user with access to a valid SAML response may impersonate another user under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68756 json | Not Provided | 2026-08-12 | 2026-08-13 | |
| CVE-2026-68755 json | A bundle writer may create misleading release promotion information under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68754 json | A repository publisher without delete permission may modify protected package content under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68753 json | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a sp... | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-68752 json | A Project Resource Manager may gain broader administrative privileges under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66384 json | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | Not Provided | 2026-08-12 | 2026-08-28 |
| CVE-2026-66382 json | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66381 json | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditi... | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66380 json | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66379 json | An authenticated user may view private Puppet module metadata without repository read access. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66378 json | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
| CVE-2026-66377 json | An unauthenticated user may access restricted repository information under specific conditions. | Not Provided | 2026-08-12 | 2026-09-02 |
Known software with vulnerabilities from Jfrog
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jfrog | Artifactory | 1.0 |