Junglewise Threat Intelligence

CVE-2026-70550: JFrog Artifactory authorization bypass in Composer repository handling

CVE-2026-70550 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: JFrog Artifactory. Vendors: JFrog.

Executive brief

JFrog Artifactory is a widely-used artifact management platform that stores and manages software packages and dependencies. This vulnerability allows authenticated users to read package metadata from repositories they should not have access to, potentially exposing sensitive information about internal packages and their versions. While authentication is required, the impact is a breach of confidentiality through unauthorized metadata disclosure.

Technical details

The vulnerability is an authorization bypass in the Composer package repository handling logic within Artifactory. An authenticated user can circumvent repository-level access controls under specific conditions to read package metadata from repositories they are not authorized to access. The attack requires valid authentication credentials but does not require elevated privileges. The vulnerability affects confidentiality by allowing unauthorized disclosure of package names, versions, and associated metadata. Fixes are available in Artifactory versions 7.161.12 and later, and 7.146.36 and later.

Affected products

  • JFrog Artifactory 7.161.0 to 7.161.11, 7.146.0 to 7.146.35

Timeline

  • 2026-08-25: disclosed

References

Related threats