Junglewise Threat Intelligence

CVE-2026-70548: JFrog Artifactory external dependency information disclosure in CocoaPods

CVE-2026-70548 · Severity: low · CVSS 3.5 · Published 2026-08-25

Technologies: JFrog Artifactory. Vendors: JFrog.

Executive brief

JFrog Artifactory is a software repository manager that stores and distributes code packages. Under specific circumstances, a low-privileged user can trigger requests to remote CocoaPods repositories (a package manager for Apple development), potentially allowing unauthorized access to external repository information that they should not be able to reach.

Technical details

This vulnerability exists in JFrog Artifactory's handling of external dependencies for CocoaPods repositories. A low-privileged authenticated user can craft requests that are forwarded to remote CocoaPods repositories without proper authorization validation, allowing them to interact with external package sources they are not entitled to access. The vulnerability requires specific configuration conditions and an authenticated user account to exploit. Patches are available in Artifactory versions 7.161.17+, 7.146.30+, and newer release branches.

Affected products

  • JFrog Artifactory 7.161.0–7.161.1, 7.161.11–7.161.16, 7.146.0–7.146.29

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory

References

Related threats