Information Disclosure in JFrog Artifactory Affected by Anonymous Access
CVE-2026-65926
3.1LOW
What is CVE-2026-65926?
An information disclosure vulnerability exists in JFrog Artifactory that allows an anonymous caller or a low-privilege authenticated user to identify private Release Bundle names and versions when they already know the bundle name. This flaw arises when anonymous access is enabled, potentially exposing sensitive information to unauthorized users. It's crucial for organizations to review their access configurations and apply necessary security measures to mitigate this risk.
Affected Version(s)
artifactory 0 < 7.146.35
artifactory 7.161.0 < 7.161.16
