JFrog Artifactory 7.18.3: known vulnerabilities
53 known CVEs affect JFrog Artifactory 7.18.3: 48 by NVD's exact CPE match, and 5 more that JFrog's advisories list and NVD has not analyzed.
NVD's count evaluates NVD's published version ranges against this version; those ranges do not carry JFrog's per-branch fixes, so the NVD column can read the same on either side of a fix that JFrog names. Where NVD has not analyzed a record, the row reads "no NVD data", not "no".
- Known CVEs
- 53
- Critical 4 High 17 Medium 30 Low 2
- 4 critical, 17 high, 30 medium, 2 low
- Released
- April 22, 2021
- Per JFrog's release pages.
- End of life
- End of life was October 22, 2022 per JFrog's end-of-life table.
- Behind latest
- 1,972 days behind 7.161.29 (released September 15, 2026).
JFrog's policy: JFrog supports self-managed versions of Artifactory for 18 months from the release of the initial minor version.
Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), JFrog's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.
CVEs that affect 7.18.3 (53)
Two verdicts per row, side by side: what NVD's exact CPE match says, and what JFrog's own CVE record says. A CVE counts when either source says affected. Open a row's sources for the raw ranges.
| CVE | Severity | Affected per NVD | Affected per JFrog | Fix on your branch |
|---|---|---|---|---|
| CVE-2022-0668 published January 8, 2023 JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user. | Critical9.8 CVSS 3.1 9.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.37.13. Latest: 7.161.29. |
Sources for CVE-2022-0668 and 7.18.3 Hide sources
| ||||
| CVE-2026-82329 published August 28, 2026 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | Critical9.8 CVSS 3.1 9.8, rated by JFrog (CNA) | no | yes | No fix on your branch; the nearest fix is 7.111.21. Latest: 7.161.29. |
Sources for CVE-2026-82329 and 7.18.3 Hide sources
| ||||
| CVE-2024-6915 published August 5, 2024 JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning. | Critical9.3 CVSS 3.1 9.3, rated by JFrog (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 7.55.18. Latest: 7.161.29. |
Sources for CVE-2024-6915 and 7.18.3 Hide sources
| ||||
| CVE-2024-4142 published May 1, 2024 An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled. | Critical9.0 CVSS 3.1 9.0, rated by JFrog (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 7.55.17. Latest: 7.161.29. |
Sources for CVE-2024-4142 and 7.18.3 Hide sources
| ||||
| CVE-2021-23163 published July 6, 2022 JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.33.6. Latest: 7.161.29. |
Sources for CVE-2021-23163 and 7.18.3 Hide sources
| ||||
| CVE-2021-3860 published December 20, 2021 JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.25.4. Latest: 7.161.29. |
Sources for CVE-2021-3860 and 7.18.3 Hide sources
| ||||
| CVE-2022-0573 published May 16, 2022 JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.36.1. Latest: 7.161.29. |
Sources for CVE-2022-0573 and 7.18.3 Hide sources
| ||||
| CVE-2023-42661 published March 7, 2024 JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.76.2. Latest: 7.161.29. |
Sources for CVE-2023-42661 and 7.18.3 Hide sources
| ||||
| CVE-2026-42016 published July 27, 2026 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.133.11. Latest: 7.161.29. |
Sources for CVE-2026-42016 and 7.18.3 Hide sources
| ||||
| CVE-2026-42017 published July 27, 2026 An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. | High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.133.21. Latest: 7.161.29. |
Sources for CVE-2026-42017 and 7.18.3 Hide sources
| ||||
| CVE-2026-65616 published July 27, 2026 Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. | High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.27. Latest: 7.161.29. |
Sources for CVE-2026-65616 and 7.18.3 Hide sources
| ||||
| CVE-2026-65617 published July 27, 2026 A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65617 and 7.18.3 Hide sources
| ||||
| CVE-2026-65921 published July 27, 2026 A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. | High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65921 and 7.18.3 Hide sources
| ||||
| CVE-2026-66014 published July 27, 2026 JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. | High8.8 CVSS 3.1 8.8, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-66014 and 7.18.3 Hide sources
| ||||
| CVE-2026-69106 published August 12, 2026 A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.28. Latest: 7.161.29. |
Sources for CVE-2026-69106 and 7.18.3 Hide sources
| ||||
| CVE-2026-66375 published August 12, 2026 A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | High8.1 CVSS 3.1 8.1, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66375 and 7.18.3 Hide sources
| ||||
| CVE-2023-42509 published March 7, 2024 JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data. | High7.5 CVSS 3.1 7.5, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.77.0. Latest: 7.161.29. |
Sources for CVE-2023-42509 and 7.18.3 Hide sources
| ||||
| CVE-2026-42018 published August 12, 2026 JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | High7.5 CVSS 3.1 7.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.20. Latest: 7.161.29. |
Sources for CVE-2026-42018 and 7.18.3 Hide sources
| ||||
| CVE-2026-68757 published August 12, 2026 A user with access to a valid SAML response may impersonate another user under specific conditions. | High7.5 CVSS 3.1 7.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68757 and 7.18.3 Hide sources
| ||||
| CVE-2026-68752 published August 12, 2026 A Project Resource Manager may gain broader administrative privileges under specific conditions. | High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68752 and 7.18.3 Hide sources
| ||||
| CVE-2026-68759 published August 12, 2026 A holder of a valid integration credential may impersonate other users under specific conditions. | High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68759 and 7.18.3 Hide sources
| ||||
| CVE-2026-65923 published July 27, 2026 A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions. | Medium6.8 CVSS 3.1 6.8, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65923 and 7.18.3 Hide sources
| ||||
| CVE-2026-66016 published August 12, 2026 Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | Medium6.7 CVSS 3.1 6.7, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66016 and 7.18.3 Hide sources
| ||||
| CVE-2026-68756 published August 12, 2026 A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | Medium6.6 CVSS 3.1 6.6, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68756 and 7.18.3 Hide sources
| ||||
| CVE-2021-41834 published May 23, 2022 JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. | Medium6.5 CVSS 3.1 6.5, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.28.0. Latest: 7.161.29. |
Sources for CVE-2021-41834 and 7.18.3 Hide sources
| ||||
| CVE-2023-42508 published October 3, 2023 JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body. | Medium6.5 CVSS 3.1 6.5, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.66.0. Latest: 7.161.29. |
Sources for CVE-2023-42508 and 7.18.3 Hide sources
| ||||
| CVE-2026-65618 published July 27, 2026 Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data. | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.133.6. Latest: 7.161.29. |
Sources for CVE-2026-65618 and 7.18.3 Hide sources
| ||||
| CVE-2026-65924 published July 27, 2026 JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content. | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65924 and 7.18.3 Hide sources
| ||||
| CVE-2026-65925 published July 27, 2026 A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65925 and 7.18.3 Hide sources
| ||||
| CVE-2026-68754 published August 12, 2026 A repository publisher without delete permission may modify protected package content under specific conditions. | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68754 and 7.18.3 Hide sources
| ||||
| CVE-2026-68758 published August 12, 2026 A low-privileged authenticated user may access restricted support information under specific conditions. | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68758 and 7.18.3 Hide sources
| ||||
| CVE-2024-2248 published May 15, 2024 A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email. | Medium6.4 CVSS 3.1 6.4, rated by JFrog (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 7.84.7. Latest: 7.161.29. |
Sources for CVE-2024-2248 and 7.18.3 Hide sources
| ||||
| CVE-2021-45721 published July 6, 2022 JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38. | Medium6.1 CVSS 3.1 6.1, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.29.8. Latest: 7.161.29. |
Sources for CVE-2021-45721 and 7.18.3 Hide sources
| ||||
| CVE-2024-2247 published March 13, 2024 JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism. | Medium6.1 CVSS 3.1 6.1, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.77.7. Latest: 7.161.29. |
Sources for CVE-2024-2247 and 7.18.3 Hide sources
| ||||
| CVE-2026-69107 published August 12, 2026 An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | Medium5.9 CVSS 3.1 5.9, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.104.16. Latest: 7.161.29. |
Sources for CVE-2026-69107 and 7.18.3 Hide sources
| ||||
| CVE-2021-45074 published March 2, 2022 JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session. | Medium5.4 CVSS 3.1 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.29.3. Latest: 7.161.29. |
Sources for CVE-2021-45074 and 7.18.3 Hide sources
| ||||
| CVE-2026-65922 published July 27, 2026 An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected. | Medium5.4 CVSS 3.1 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29. |
Sources for CVE-2026-65922 and 7.18.3 Hide sources
| ||||
| CVE-2026-66376 published August 12, 2026 Credentials for a deleted user may remain valid for a short period under specific conditions. | Medium5.4 CVSS 3.1 5.4, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66376 and 7.18.3 Hide sources
| ||||
| CVE-2026-66377 published August 12, 2026 An unauthenticated user may access restricted repository information under specific conditions. | Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66377 and 7.18.3 Hide sources
| ||||
| CVE-2026-66381 published August 12, 2026 A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | Medium5.3 CVSS 3.1 5.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66381 and 7.18.3 Hide sources
| ||||
| CVE-2026-66384 published August 12, 2026 An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66384 and 7.18.3 Hide sources
| ||||
| CVE-2026-68753 published August 12, 2026 An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. | Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68753 and 7.18.3 Hide sources
| ||||
| CVE-2026-68760 published August 12, 2026 An unauthenticated user may bypass authentication under specific cache conditions. | Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68760 and 7.18.3 Hide sources
| ||||
| CVE-2021-45730 published May 19, 2022 JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29. |
Sources for CVE-2021-45730 and 7.18.3 Hide sources
| ||||
| CVE-2021-46687 published July 6, 2022 JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | Medium4.9 CVSS 3.1 4.9, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29. |
Sources for CVE-2021-46687 and 7.18.3 Hide sources
| ||||
| CVE-2024-3505 published April 15, 2024 JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments. | Medium4.3 CVSS 3.1 4.3, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.77.3. Latest: 7.161.29. |
Sources for CVE-2024-3505 and 7.18.3 Hide sources
| ||||
| CVE-2026-66378 published August 12, 2026 An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66378 and 7.18.3 Hide sources
| ||||
| CVE-2026-66379 published August 12, 2026 An authenticated user may view private Puppet module metadata without repository read access. | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66379 and 7.18.3 Hide sources
| ||||
| CVE-2026-66380 published August 12, 2026 An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66380 and 7.18.3 Hide sources
| ||||
| CVE-2026-66382 published August 12, 2026 An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-66382 and 7.18.3 Hide sources
| ||||
| CVE-2026-68755 published August 12, 2026 A bundle writer may create misleading release promotion information under specific conditions. | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | yes | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-68755 and 7.18.3 Hide sources
| ||||
| CVE-2026-65926 published August 12, 2026 An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known. | Low3.1 CVSS 3.1 3.1, rated by JFrog (CNA) | no NVD data | yes | No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29. |
Sources for CVE-2026-65926 and 7.18.3 Hide sources
| ||||
| CVE-2021-46270 published March 2, 2022 JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation. | Low2.7 CVSS 3.1 2.7, rated by NVD | yes | yes | No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29. |
Sources for CVE-2021-46270 and 7.18.3 Hide sources
| ||||
10 other JFrog Artifactory CVEs on record that do not affect 7.18.3
Each of these is fixed at or before 7.18.3 on its branch, or its published range does not include this version. The fix column shows the fix this version already carries.
| CVE | Severity | Affected per NVD | Affected per JFrog | Fix on your branch |
|---|---|---|---|---|
| CVE-2026-70551 published August 25, 2026 | High8.5 CVSS 3.1 8.5, rated by JFrog (CNA) | no NVD data | no | This version predates the affected range (from 7.146.0). |
Sources for CVE-2026-70551 and 7.18.3 Hide sources
| ||||
| CVE-2026-69105 published August 12, 2026 | High8.1 CVSS 3.1 8.1, rated by JFrog (CNA) | no | no | This version predates the affected range (from 7.161.0). |
Sources for CVE-2026-69105 and 7.18.3 Hide sources
| ||||
| CVE-2026-69104 published August 25, 2026 | High7.6 CVSS 3.1 7.6, rated by JFrog (CNA) | no NVD data | no | This version predates the affected range (from 7.161.0). |
Sources for CVE-2026-69104 and 7.18.3 Hide sources
| ||||
| CVE-2026-66015 published July 27, 2026 | High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) | no | no | This version predates the affected range (from 7.146.0). |
Sources for CVE-2026-66015 and 7.18.3 Hide sources
| ||||
| CVE-2023-42662 published March 7, 2024 | Medium6.5 CVSS 3.1 6.5, rated by NVD | no | no | This version predates the affected range (from 7.59.0). |
Sources for CVE-2023-42662 and 7.18.3 Hide sources
| ||||
| CVE-2026-66018 published July 27, 2026 | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | no | no | This version predates the affected range (from 7.146.0). |
Sources for CVE-2026-66018 and 7.18.3 Hide sources
| ||||
| CVE-2026-70550 published August 25, 2026 | Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) | no NVD data | no | This version predates the affected range (from 7.146.0). |
Sources for CVE-2026-70550 and 7.18.3 Hide sources
| ||||
| CVE-2025-14830 published January 4, 2026 | Medium4.9 CVSS 3.1 4.9, rated by JFrog (CNA) | no NVD data | no | This version predates the affected range (from 7.94.0). |
Sources for CVE-2025-14830 and 7.18.3 Hide sources
| ||||
| CVE-2026-70547 published August 12, 2026 | Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) | no | no | This version predates the affected range (from 7.161.0). |
Sources for CVE-2026-70547 and 7.18.3 Hide sources
| ||||
| CVE-2026-70548 published August 25, 2026 | Low3.5 CVSS 3.1 3.5, rated by JFrog (CNA) | no NVD data | no | This version predates the affected range (from 7.146.0). |
Sources for CVE-2026-70548 and 7.18.3 Hide sources
| ||||
About this page and CloudRepo
CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.
Read next
Look up another version