Authorization Weakness in JFrog Artifactory Affecting Metadata Handling
CVE-2026-65922

7.1HIGH

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65922?

An authorization weakness in the internal metadata handling of JFrog Artifactory allows users with restricted repository access to write into sensitive internal metadata areas under specific circumstances. This vulnerability primarily affects the integrity and availability of the system, although it does not compromise confidentiality. Users should be aware of this potential exposure in their environments, particularly in multi-user systems.

Affected Version(s)

artifactory 0 < 7.111.18

artifactory 7.117.0 < 7.117.25

artifactory 7.125.0 < 7.125.18

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Uri Katz | Oligo Security
.