Executive brief
JFrog Artifactory, a platform for managing software packages and artifacts, contains a security flaw in how it handles internal metadata. An authorized user with limited access to a repository could exploit this weakness to modify restricted internal data. While this does not allow the theft of sensitive information, it could allow an attacker to compromise the integrity of the system or cause service disruptions.
Technical details
A missing authorization vulnerability (CWE-862) exists in JFrog Artifactory's internal metadata handling. The flaw allows an authenticated attacker with low-level repository permissions to bypass intended access controls and write to restricted internal metadata areas. The attack is network-reachable and requires no user interaction, though it does require valid credentials. Exploitation primarily impacts the integrity of the metadata and the availability of the service, while data confidentiality remains unaffected. JFrog has released several patched versions across different release branches, including 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15.
Affected products
- JFrog Artifactory Self-Managed < 7.111.18, 7.117.0 to < 7.117.25, 7.125.0 to < 7.125.18, 7.133.0 to < 7.133.27, 7.146.0 to < 7.146.34, 7.161.0 to < 7.161.15
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched