JFrog
- 9
- vulnerabilities tracked
- 2
- under active exploitation
- 2 September 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-82329JFrog Artifactory Improper Authentication VulnerabilityJFrog Artifactory Critical CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory VulnerabilityJFrog Artifactory Critical CVE-2026-42016JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.Jfrog Artifactory High CVSS 8.1 CVE-2026-42017An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.Jfrog Artifactory High CVSS 8.8 CVE-2026-65616Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.Jfrog Artifactory High CVSS 8.8 CVE-2026-65617A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.Jfrog Artifactory High CVSS 8.8 CVE-2026-65921A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.Jfrog Artifactory High CVSS 8.8 CVE-2026-66014JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.Jfrog Artifactory High CVSS 8.8 CVE-2026-66015An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.Jfrog Artifactory High CVSS 7.2