Information Disclosure in JFrog Artifactory Affected by Anonymous Access
CVE-2026-65926

3.1LOW

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-65926?

An information disclosure vulnerability exists in JFrog Artifactory that allows an anonymous caller or a low-privilege authenticated user to identify private Release Bundle names and versions when they already know the bundle name. This flaw arises when anonymous access is enabled, potentially exposing sensitive information to unauthorized users. It's crucial for organizations to review their access configurations and apply necessary security measures to mitigate this risk.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khai Tran | OpenAI
.