CVE-2026-70550: CWE-862 Missing Authorization in jfrog artifactory
Description
CVE-2026-70550 is an authorization vulnerability in JFrog Artifactory's handling of Composer repositories. It allows an authenticated user, under certain conditions, to read package metadata from repositories they are not authorized to access. This issue impacts the confidentiality of repository data. The vulnerability has been addressed in fixed versions of Artifactory.
CVSS v3.1
Score 6.5medium
Affected software
jfrog
artifactory
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-70550) involves a missing authorization check in JFrog Artifactory's Composer repository functionality. Authenticated users may exploit this weakness to access package metadata from unauthorized repositories, potentially exposing sensitive information. The flaw affects confidentiality but does not impact integrity or availability. The issue has been fixed in updated versions of Artifactory.
Potential Impact
The vulnerability compromises confidentiality by allowing unauthorized read access to package metadata within Composer repositories. There is no impact on integrity or availability. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available as the vulnerability has been addressed in updated versions of JFrog Artifactory. Users should upgrade to the fixed versions to remediate this issue. Since this is not a cloud service, remediation depends on applying the vendor's patch. Patch status is not explicitly detailed in the provided data; users should consult the vendor advisory for exact fixed versions and update instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- JFROG
- Date Reserved
- 2026-08-04T18:29:25.512Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8dba55acd9273b4965b67e
Added to database: 08/25/2026, 15:52:53 UTC
Last enriched: 09/10/2026, 18:24:32 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.