CVE-2026-70550
Potential unauthorized access to private Composer repository metadata in JFrog Artifactory
Description
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
INFO
Published Date :
Aug. 25, 2026, 3:22 p.m.
Last Modified :
Aug. 25, 2026, 3:22 p.m.
Remotely Exploit :
Yes !
Source :
JFROG
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | 48a46f29-ae42-4e1d-90dd-c1676c1e5e6d |
Solution
- Update JFrog Artifactory to a fixed version.
- Verify Composer repository access controls.
- Review access logs for suspicious activity.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-70550 vulnerability anywhere in the article.