Remote Access Vulnerability in JFrog Artifactory by JFrog
CVE-2026-70548

3.5LOW

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
25 August 2026

What is CVE-2026-70548?

A vulnerability has been identified in JFrog Artifactory that enables low-level users to issue requests to remote CocoaPods repositories. This may lead to unauthorized access and exposure of sensitive information. It is crucial for users of affected versions to review their configurations and implement appropriate access controls to mitigate potential risks.

Affected Version(s)

artifactory 7.161.11 < 7.161.19

artifactory 7.146.0 < 7.146.36

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kostya Kortchinsky | OpenAI
.