CVE-2026-70551: CWE-918 Server-Side request forgery (SSRF) in jfrog artifactory
Description
CVE-2026-70551 is a high severity server-side request forgery (SSRF) vulnerability in JFrog Artifactory. It allows a user with read access to an existing remote VCS repository to replace its configured origin or supply an absolute VCS data URL, potentially leading to unauthorized access to internal resources or data leakage. The vulnerability affects specific versions of Artifactory, including 7.146.0 and 7.161.0. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.
CVSS v3.1
Score 8.5high
Affected software
jfrog
artifactory
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-70551) in JFrog Artifactory involves CWE-918 (Server-Side Request Forgery). A user who can read an existing remote Version Control System (VCS) repository can manipulate the repository's configured origin or provide an absolute VCS data URL. This manipulation can cause the server to make unintended requests, potentially exposing internal network resources or sensitive data. The CVSS v3.1 score is 8.5, indicating high severity, with network attack vector, low attack complexity, low privileges required, no user interaction, and impact including high confidentiality loss, limited integrity loss, and no availability impact. The affected versions explicitly include 7.146.0 and 7.161.0. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with read access to a remote VCS repository in affected versions of JFrog Artifactory can exploit this SSRF vulnerability to cause the server to make unauthorized requests. This can lead to high confidentiality impact by potentially exposing sensitive internal resources or data. Integrity impact is limited, and availability is not affected. The vulnerability could be leveraged to bypass network restrictions or access internal services not normally reachable by the attacker.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict read access to remote VCS repositories to trusted users only and monitor for unusual repository configuration changes. Avoid exposing Artifactory instances to untrusted networks. Follow vendor updates closely for any forthcoming patches or mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- JFROG
- Date Reserved
- 2026-08-04T18:29:25.512Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8db46cacd9273b495e7a33
Added to database: 08/25/2026, 15:27:40 UTC
Last enriched: 09/10/2026, 04:37:07 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.