Executive brief
JFrog Artifactory, a platform used by organizations to manage and store software building blocks (artifacts), contains a security flaw in how it handles internal requests. An attacker with basic user access could exploit this weakness to gain higher-level administrative permissions. This could allow unauthorized individuals to access sensitive software code, modify production packages, or disrupt the software delivery pipeline.
Technical details
JFrog Artifactory is vulnerable to improper authentication (CWE-287) within its internal request processing logic. The flaw allows a remote attacker with low-privileged credentials (PR:L) to bypass intended access controls and escalate their privileges to a higher level, potentially gaining administrative control over the platform. The vulnerability is reachable over the network without user interaction. JFrog has released several patched versions across different release branches, including 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15.
Affected products
- JFrog Artifactory Self-Managed < 7.111.18, 7.117.0 to < 7.117.25, 7.125.0 to < 7.125.18, 7.133.0 to < 7.133.27, 7.146.0 to < 7.146.34, 7.161.0 to < 7.161.15
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched: Fixed in Artifactory 7.161.15 and other maintenance releases.