SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-70550

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An authorization weakness in JFrog Artifactory's handling of Composer repositories allows authenticated users to potentially access package metadata from unauthorized repositories, compromising confidentiality. Organizations using affected versions of Artifactory should prioritize applying the available fixes to mitigate this risk. This vulnerability is particularly relevant for teams managing sensitive package data and access controls within their development environments.

CVE
CVE-2026-70550
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.