Executive brief
JFrog Artifactory is a package repository manager used by development teams to store and distribute software artifacts. An authenticated user without read access to specific repositories can bypass permission controls to view package metadata they should not be able to access. While the direct exposure is limited to metadata rather than package content itself, this could reveal information about internal projects or dependencies an organization intends to keep private.
Technical details
This is an authorization bypass vulnerability in JFrog Artifactory's package repository access control. An authenticated user without read permission on a repository can access package metadata through unspecified conditions. The vulnerability requires an attacker to be authenticated, but does not require any particular privilege level or special preconditions beyond repository authentication. An attacker can retrieve metadata that should be protected by repository access controls, potentially exposing information about private packages, versions, or internal dependencies. The vulnerability has been patched in Artifactory versions 7.161.17+ and 7.146.36+.
Affected products
- JFrog Artifactory 7.161.0 to 7.161.16
Timeline
- 2026-08-12: disclosed
- 2026-08-13: advisory