CVE-2026-65922

HIGH

Potential unauthorized modification of Artifactory internal metadata

Title source: cna
STIX 2.1

Description

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.

References (2)

Core 2

Scores

CVSS v3 7.1
EPSS 0.0020
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
jfrog/artifactory < 7.111.18 (2 CPE variants)
jfrog/artifactory 7.117.0 - 7.117.25
jfrog/artifactory 7.125.0 - 7.125.18
jfrog/artifactory 7.133.0 - 7.133.27
jfrog/artifactory 7.146.0 - 7.146.34
jfrog/artifactory 7.161.0 - 7.161.15
Published Jul 27, 2026
Tracked Since Jul 28, 2026