Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-70550
Artifactory Schwachstellenanalyse und -minderung

Überblick

CVE-2026-70550 is a missing authorization vulnerability in JFrog Artifactory's Composer repository handling that may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to access. It affects JFrog Artifactory self-managed versions 7.161.0 through 7.161.11 and versions prior to 7.146.29 (in the 7.146.x branch). The vulnerability was published on August 25, 2026, and patched versions were released the same day. It carries a CVSS v3.1 base score of 6.5 (Medium) (JFrog Advisory, Github Advisory).

Technische Details

The root cause is classified as CWE-862 (Missing Authorization): the Composer repository handling logic in Artifactory fails to enforce proper authorization checks when an authenticated user requests package metadata, allowing access to repositories outside their permitted scope under specific conditions (JFrog Advisory, Github Advisory). The attack vector is network-based, requires low privileges (a valid authenticated account), no user interaction, and low attack complexity. No public proof-of-concept or detailed technical write-up describing the specific triggering conditions has been disclosed.

Aufprall

Successful exploitation is limited to a confidentiality impact — an authenticated low-privileged user could read package metadata (e.g., package names, versions, dependencies) from Composer repositories they are not authorized to access. There is no integrity or availability impact. While the exposed data is metadata rather than package content itself, unauthorized visibility into private repository metadata could facilitate reconnaissance, supply chain mapping, or targeted attacks against internal software dependencies (JFrog Advisory, Github Advisory).

Ausnutzbarkeit

There is no evidence of active in-the-wild exploitation, and no public proof-of-concept exploit has been identified (Github Advisory). The EPSS score is approximately 0.209% (11th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment classifies exploitation as 'none' and the technical impact as 'partial' (JFrog Advisory).

Risikominderung und Problemumgehungen

JFrog has released patched versions addressing this vulnerability. Self-managed users should upgrade to Artifactory 7.161.19 (for the 7.161.x branch) or 7.146.36 (for the 7.146.x branch). JFrog Cloud environments have already been automatically patched and require no action. No specific configuration-based workaround has been published for this CVE; upgrading to a fixed version is the recommended remediation (JFrog Advisory, Artifactory Releases).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Artifactory Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-82329CRITICAL9.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
JaJaAug 28, 2026
CVE-2026-70551HIGH8.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NeinJaAug 25, 2026
CVE-2026-69104HIGH7.6
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NeinJaAug 25, 2026
CVE-2026-70550MEDIUM6.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NeinJaAug 25, 2026
CVE-2026-70548LOW3.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NeinJaAug 25, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement