CVE-2026-70547
Artifactory vulnerability analysis and mitigation

Overview

CVE-2026-70547 is a missing authorization vulnerability in JFrog Artifactory that allows an authenticated user without repository read permission to access package metadata under specific conditions. It affects JFrog Artifactory versions 7.161.0 through 7.161.15 (fixed in 7.161.16), and is classified as Medium severity with a CVSS v3.1 base score of 4.3 (Github Advisory, JFrog Advisories). The vulnerability was published on August 12, 2026, and a patch was made available the same day with the release of Artifactory 7.161.16 (JFrog Self-Managed Releases).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the product fails to perform an adequate authorization check when an authenticated actor attempts to access package metadata resources they should not have permission to view (Github Advisory). The attack vector is network-based, requires low privileges (a valid authenticated account), no user interaction, and low attack complexity, making it straightforward for any authenticated user to attempt. Exploitation occurs under "specific conditions" related to the Packages component, though JFrog has not publicly disclosed the precise endpoint or conditions that trigger the authorization bypass (JFrog Self-Managed Releases). No public proof-of-concept code has been identified.

Impact

Successful exploitation results in a limited confidentiality impact: an authenticated user without the appropriate repository read permission can read package metadata they are not authorized to access. There is no impact on integrity or availability, and the scope is unchanged, meaning the exposure is confined to the Artifactory instance itself (Github Advisory). In environments where package metadata contains sensitive information (e.g., internal package names, version details, or dependency structures), this could facilitate reconnaissance for further attacks or expose proprietary software supply chain information.

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Github Advisory). The EPSS score is approximately 0.204% (0.00204), placing it in the 11th percentile for exploitation likelihood within 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment indicates exploitation is "none" and the attack is not automatable (Feedly).

Mitigation and workarounds

JFrog has released a fix in Artifactory Self-Managed version 7.161.16, released August 12, 2026; upgrading to this version is the recommended remediation (JFrog Self-Managed Releases). Administrators should also review repository access controls and ensure users are assigned only the permissions they require. Monitoring Artifactory access logs for unexpected package metadata access by low-privilege accounts is advised as a compensating control (JFrog Advisories).

Additional resources


SourceThis report was generated using AI

Related Artifactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69106HIGH8.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69105HIGH8.1
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-42018HIGH7.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69107MEDIUM5.9
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-70547MEDIUM4.3
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management