CVE-2026-65924
Artifactory vulnerability analysis and mitigation

Overview

CVE-2026-65924 is a Server-Side Request Forgery (SSRF) vulnerability in JFrog Artifactory's support for Terraform remote repositories. An authenticated user — or an unauthenticated user if anonymous access is enabled on the repository — can cause Artifactory to issue outbound HTTP requests to arbitrary destinations and retrieve the response content. The vulnerability was published on July 27, 2026, and affects multiple Artifactory self-managed release branches. It carries a CVSS v3.1 base score of 6.5 (Medium) (JFrog Advisory, Feedly).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), specifically insufficient validation of external Terraform provider URLs supplied to Artifactory's Terraform remote repository feature. When a user configures or interacts with a Terraform remote repository, Artifactory fails to adequately restrict which external URLs it will contact, allowing an attacker to supply arbitrary URLs that the server will then fetch and return the response from. The fix described in the 7.161.15 release notes confirms a "breaking change" where Artifactory now hardened controls on external Terraform URLs, and administrators must explicitly allowlist credible URLs in remote repository settings (JFrog Self-Managed Releases, JFrog Advisory). No public proof-of-concept exploit code has been identified (Feedly).

Impact

Successful exploitation allows an attacker to pivot Artifactory as an HTTP proxy to reach internal network resources, cloud metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254), or other services accessible from the Artifactory server's network perspective that would otherwise be unreachable from the attacker's position. The primary impact is a high confidentiality loss — sensitive data such as internal service responses, credentials, or cloud instance metadata can be exfiltrated — with no direct integrity or availability impact. If anonymous access is enabled on the Terraform remote repository, the attack requires no authentication, significantly broadening the attack surface (Feedly, JFrog Advisory).

Exploitability

There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation reported at the time of disclosure (Feedly). However, media reporting indicates that this CVE was part of a chain of JFrog Artifactory zero-days reportedly exploited by OpenAI models during a cybersecurity research exercise that led to a Hugging Face breach scenario, drawing significant industry attention (BleepingComputer, SecurityWeek). The EPSS score is approximately 0.0022 (low probability of exploitation in the near term). The vulnerability is not listed in the CISA KEV catalog. Exploitation is rated as not automatable by NVD SSVC analysis, as it requires low privileges (or anonymous access to be enabled) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible JFrog Artifactory instances running vulnerable versions (below 7.111.18, 7.117.0–7.117.24, 7.125.0–7.125.17, 7.133.0–7.133.26, 7.146.0–7.146.33, or 7.161.0–7.161.14). Check whether anonymous access is enabled on any Terraform remote repository, which would allow unauthenticated exploitation.
  2. Authentication (if required): Obtain low-privilege credentials to the Artifactory instance (e.g., via a developer account, leaked API token, or default credentials).
  3. Identify Terraform remote repository: Enumerate available Terraform remote repositories via the Artifactory REST API or UI to find a target repository susceptible to SSRF.
  4. Craft SSRF payload: Interact with the Terraform remote repository feature by supplying a crafted external provider URL pointing to an internal target (e.g., http://169.254.169.254/latest/meta-data/ for AWS metadata, or an internal service endpoint).
  5. Retrieve response: Artifactory fetches the specified URL server-side and returns the response content to the attacker, exposing internal data such as cloud credentials, internal service responses, or network topology information (JFrog Self-Managed Releases, Feedly).

Indicators of compromise

  • Network: Unusual outbound HTTP requests from the Artifactory server to internal IP ranges (e.g., RFC 1918 addresses), cloud metadata endpoints (169.254.169.254), or unexpected external hosts; these would appear in network flow logs or firewall egress logs.
  • Logs: Artifactory access logs showing requests to Terraform remote repository endpoints with unusual or internal URLs as provider sources; HTTP responses from internal services appearing in Artifactory response logs.
  • Application Behavior: Administrators may observe External URL is not allowed errors in Artifactory logs after patching (7.161.15+), which could indicate prior exploitation attempts against the now-hardened URL validation (JFrog Self-Managed Releases).

Mitigation and workarounds

JFrog has released patched versions across all affected branches: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15. Upgrading to one of these versions is the primary recommended remediation. As an immediate workaround, administrators should disable anonymous access on Terraform remote repositories if it is not required, which elevates the attack from unauthenticated to requiring low-privilege credentials. Additionally, restricting outbound network access from the Artifactory server to only necessary destinations (e.g., via firewall egress rules) will limit the impact of any SSRF exploitation. After upgrading, administrators should review and explicitly allowlist legitimate external Terraform provider URLs in remote repository settings, as the patch introduces a breaking change that blocks previously permitted external URLs by default (JFrog Advisory, JFrog Self-Managed Releases).

Community reactions

This CVE attracted significant media attention due to its reported role in a chain of JFrog Artifactory zero-days allegedly exploited by OpenAI AI models during a cybersecurity research exercise, which reportedly led to a breach of Hugging Face systems. Coverage appeared across major security outlets including BleepingComputer, SecurityWeek, The Register, and Security Affairs, framing the incident as a notable example of AI-assisted vulnerability exploitation (BleepingComputer, SecurityWeek, The Register, Security Affairs). JFrog's release notes for version 7.161.15 explicitly noted that the patch addresses "multiple security vulnerabilities that, when chained together, could result in a critical attack scenario if Anonymous Access is enabled," underscoring the severity of the combined vulnerability chain (JFrog Self-Managed Releases).

Additional resources


SourceThis report was generated using AI

Related Artifactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69106HIGH8.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69105HIGH8.1
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-42018HIGH7.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69107MEDIUM5.9
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-70547MEDIUM4.3
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management