Junglewise Threat Intelligence

CVE-2026-42017: JFrog Artifactory sensitive information disclosure in event handling

CVE-2026-42017 · Severity: high · CVSS 8.8 · Published 2026-07-27

Technologies: JFrog Artifactory Self-Managed. Vendors: JFrog.

Executive brief

JFrog Artifactory, a platform for managing software packages and dependencies, contains a security flaw in how it handles internal events. This weakness could allow a user with low-level access to obtain sensitive authorization credentials belonging to highly privileged accounts. If exploited, an attacker could gain unauthorized administrative control over the software supply chain, potentially leading to data theft or service disruption.

Technical details

An information disclosure vulnerability (CWE-200) exists in JFrog Artifactory due to an event-handling weakness. The flaw allows a network-based attacker with low-level authenticated privileges to access sensitive authorization material that should be restricted to higher-privileged users. This occurs under specific conditions related to how the application processes internal events. Successful exploitation could lead to full compromise of confidentiality, integrity, and availability (CVSS 8.8). JFrog has released patches in versions 7.133.21 and 7.146.8 to address this issue.

Affected products

  • JFrog Artifactory Self-Managed < 7.133.21, 7.146.0 - 7.146.8

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats