Executive brief
JFrog Artifactory is a widely-used artifact repository manager that stores and manages software packages and builds. A low-privileged authenticated user can access restricted support information through a specific exploitation path, potentially exposing internal system details, logs, or diagnostic data not intended for that user's access level.
Technical details
This is an authorization bypass vulnerability affecting JFrog Artifactory. A low-privileged authenticated user can circumvent access controls under specific conditions to retrieve support-related information that should be restricted to administrators or support personnel. The vulnerability is network-reachable and requires valid authentication credentials, but does not require elevated privileges. The attack allows information disclosure; no code execution or data modification is possible via this path. Patches have been released in affected version streams.
Affected products
- JFrog Artifactory <7.146.35; 7.161.0 → 7.161.16
Timeline
- 2026-08-12: disclosed