Executive brief
JFrog Artifactory, a platform for managing software packages and artifacts, contains a security flaw in how it handles certain package data. An attacker with low-level user access could exploit this weakness to compromise the confidentiality and integrity of the system or cause service disruptions. This could lead to unauthorized access to proprietary software code or the modification of trusted packages.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in JFrog Artifactory's package handling component. The flaw is rooted in the insufficient validation of serialized objects during package processing. A network-based attacker with low-privileged authentication can exploit this by submitting specially crafted payloads under specific repository conditions. Successful exploitation can lead to unauthorized data access, modification of artifacts, or a complete impact on service availability. JFrog has released several patched versions across different release branches to address this issue.
Affected products
- JFrog Artifactory Self-Managed < 7.111.18, 7.117.0 to < 7.117.25, 7.125.0 to < 7.125.18, 7.133.0 to < 7.133.27, 7.146.0 to < 7.146.34, 7.161.0 to < 7.161.15
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched: Fixed in versions 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15