JFrog Artifactory 7.5.5: known vulnerabilities

52 known CVEs affect JFrog Artifactory 7.5.5: 46 by NVD's exact CPE match, and 6 more that JFrog's advisories list and NVD has not analyzed.

NVD's count evaluates NVD's published version ranges against this version; those ranges do not carry JFrog's per-branch fixes, so the NVD column can read the same on either side of a fix that JFrog names. Where NVD has not analyzed a record, the row reads "no NVD data", not "no".

Known CVEs
52
Critical 4 High 16 Medium 30 Low 2
4 critical, 16 high, 30 medium, 2 low
Released
May 31, 2020
Per JFrog's release pages.
End of life
End of life was November 19, 2021 per JFrog's end-of-life table.
Behind latest
2,298 days behind 7.161.29 (released September 15, 2026).

JFrog's policy: JFrog supports self-managed versions of Artifactory for 18 months from the release of the initial minor version.

Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), JFrog's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.

CVEs that affect 7.5.5 (52)

Two verdicts per row, side by side: what NVD's exact CPE match says, and what JFrog's own CVE record says. A CVE counts when either source says affected. Open a row's sources for the raw ranges.

CVEs that affect JFrog Artifactory 7.5.5
CVE-2022-0668 published January 8, 2023

JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.

Critical9.8 CVSS 3.1 9.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.37.13. Latest: 7.161.29.
Sources for CVE-2022-0668 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.41; from 7.0.0 (including), before 7.37.13. NVD record
JFrog range
JFrog: prior to 7.37.13. JFrog advisory
CVE-2026-82329 published August 28, 2026

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Critical9.8 CVSS 3.1 9.8, rated by JFrog (CNA) no yes No fix on your branch; the nearest fix is 7.111.21. Latest: 7.161.29.
Sources for CVE-2026-82329 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.111.4 (including), before 7.111.21; from 7.117.0 (including), before 7.117.28; from 7.125.0 (including), before 7.125.20; from 7.133.0 (including), before 7.133.29; from 7.146.0 (including), before 7.146.38; from 7.161.0 (including), before 7.161.20. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.21; from 7.117.0 before 7.117.28; from 7.125.0 before 7.125.20; from 7.133.0 before 7.133.29; from 7.146.0 before 7.146.38; from 7.161.0 before 7.161.20. JFrog advisory
CVE-2024-6915 published August 5, 2024

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

Critical9.3 CVSS 3.1 9.3, rated by JFrog (CNA) no NVD data yes No fix on your branch; the nearest fix is 7.55.18. Latest: 7.161.29.
Sources for CVE-2024-6915 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
JFrog range
JFrog: versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18. JFrog advisory
CVE-2024-4142 published May 1, 2024

An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.

Critical9.0 CVSS 3.1 9.0, rated by JFrog (CNA) no NVD data yes No fix on your branch; the nearest fix is 7.55.17. Latest: 7.161.29.
Sources for CVE-2024-4142 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
JFrog range
JFrog's CVE record: from 0 before 7.55.17; from 0 before 7.59.22; from 0 before 7.63.21; from 0 before 7.68.21; from 0 before 7.71.21; from 0 before 7.77.11; from 0 before 7.84.6. JFrog advisory
CVE-2021-23163 published July 6, 2022

JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.33.6. Latest: 7.161.29.
Sources for CVE-2021-23163 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.38; from 7.0.0 (including), before 7.33.6. NVD record
JFrog range
JFrog: prior to version 7.33.6 and 6.23.38. JFrog advisory
CVE-2021-3860 published December 20, 2021

JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

High8.8 CVSS 3.1 8.8, rated by NVD no yes No fix on your branch; the nearest fix is 7.25.4. Latest: 7.161.29.
Sources for CVE-2021-3860 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): before 6.23.30; from 7.11.0 (including), before 7.11.8; from 7.12.0 (including), before 7.12.10; from 7.17.0 (including), before 7.17.14; from 7.18.0 (including), before 7.18.11; from 7.19.0 (including), before 7.19.12; from 7.21.0 (including), before 7.21.14; from 7.23.0 (including), before 7.23.8; from 7.24.0 (including), before 7.24.7; from 7.25.0 (including), before 7.25.4. NVD record
JFrog range
JFrog: before 7.25.4 (Enterprise+ deployments only). JFrog advisory
CVE-2022-0573 published May 16, 2022

JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.36.1. Latest: 7.161.29.
Sources for CVE-2022-0573 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.41; from 7.0.0 (including), before 7.17.16; from 7.18.0 (including), before 7.18.12; from 7.19.0 (including), before 7.19.13; from 7.21.0 (including), before 7.21.25; from 7.25.0 (including), before 7.25.9; from 7.27.0 (including), before 7.27.15; from 7.29.0 (including), before 7.29.10; from 7.31.0 (including), before 7.31.16; from 7.33.0 (including), before 7.33.12; from 7.34.0 (including), before 7.34.4; exactly 7.35.0; exactly 7.36.0. NVD record
JFrog range
JFrog: before 7.36.1 and 6.23.41. JFrog advisory
CVE-2023-42661 published March 7, 2024

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.76.2. Latest: 7.161.29.
Sources for CVE-2023-42661 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.76.2. NVD record
JFrog range
JFrog: prior to version 7.76.2. JFrog advisory
CVE-2026-42016 published July 27, 2026

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.133.11. Latest: 7.161.29.
Sources for CVE-2026-42016 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.133.11. NVD record
JFrog range
JFrog: versions before 7.133.11. JFrog advisory
CVE-2026-42017 published July 27, 2026

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.

High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.133.21. Latest: 7.161.29.
Sources for CVE-2026-42017 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.133.21; from 7.146.0 (including), before 7.146.8. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.133.21; from 7.146.0 before 7.146.8. JFrog advisory
CVE-2026-65616 published July 27, 2026

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.27. Latest: 7.161.29.
Sources for CVE-2026-65616 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.27. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.27. JFrog advisory
CVE-2026-65617 published July 27, 2026

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65617 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-65921 published July 27, 2026

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65921 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-66014 published July 27, 2026

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

High8.8 CVSS 3.1 8.8, rated by NVD yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-66014 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-69106 published August 12, 2026

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

High8.8 CVSS 3.1 8.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.28. Latest: 7.161.29.
Sources for CVE-2026-69106 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.28. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.28. JFrog advisory
CVE-2026-66375 published August 12, 2026

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

High8.1 CVSS 3.1 8.1, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66375 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-42018 published August 12, 2026

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

High7.5 CVSS 3.1 7.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.20. Latest: 7.161.29.
Sources for CVE-2026-42018 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.20; from 7.117.0 (including), before 7.117.27; from 7.125.0 (including), before 7.125.19; from 7.133.0 (including), before 7.133.28; from 7.146.0 (including), before 7.146.8. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.20; from 7.117.0 before 7.117.27; from 7.125.0 before 7.125.19; from 7.133.0 before 7.133.28; from 7.146.0 before 7.146.8. JFrog advisory
CVE-2026-68757 published August 12, 2026

A user with access to a valid SAML response may impersonate another user under specific conditions.

High7.5 CVSS 3.1 7.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68757 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68752 published August 12, 2026

A Project Resource Manager may gain broader administrative privileges under specific conditions.

High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68752 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35. JFrog advisory
CVE-2026-68759 published August 12, 2026

A holder of a valid integration credential may impersonate other users under specific conditions.

High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68759 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-65923 published July 27, 2026

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

Medium6.8 CVSS 3.1 6.8, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65923 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog: versions.. JFrog advisory
CVE-2026-66016 published August 12, 2026

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

Medium6.7 CVSS 3.1 6.7, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66016 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68756 published August 12, 2026

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

Medium6.6 CVSS 3.1 6.6, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68756 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2021-41834 published May 23, 2022

JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.

Medium6.5 CVSS 3.1 6.5, rated by NVD yes yes No fix on your branch; the nearest fix is 7.28.0. Latest: 7.161.29.
Sources for CVE-2021-41834 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): before 6.23.38; from 7.0.0 (including), before 7.28.0. NVD record
JFrog range
JFrog: prior to version 7.28.0 and 6.23.38. JFrog advisory
CVE-2023-42508 published October 3, 2023

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

Medium6.5 CVSS 3.1 6.5, rated by NVD yes yes No fix on your branch; the nearest fix is 7.66.0. Latest: 7.161.29.
Sources for CVE-2023-42508 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 7.0.0 (including), before 7.66.0. NVD record
JFrog range
JFrog: prior to version 7.66.0. JFrog advisory
CVE-2026-65618 published July 27, 2026

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.

Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.133.6. Latest: 7.161.29.
Sources for CVE-2026-65618 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.133.6. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.133.6. JFrog advisory
CVE-2026-65924 published July 27, 2026

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.

Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65924 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-65925 published July 27, 2026

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65925 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-68754 published August 12, 2026

A repository publisher without delete permission may modify protected package content under specific conditions.

Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68754 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68758 published August 12, 2026

A low-privileged authenticated user may access restricted support information under specific conditions.

Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68758 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2024-2248 published May 15, 2024

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.

Medium6.4 CVSS 3.1 6.4, rated by JFrog (CNA) no NVD data yes No fix on your branch; the nearest fix is 7.84.7. Latest: 7.161.29.
Sources for CVE-2024-2248 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
JFrog range
JFrog: versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted). JFrog advisory
CVE-2021-45721 published July 6, 2022

JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.

Medium6.1 CVSS 3.1 6.1, rated by NVD yes yes No fix on your branch; the nearest fix is 7.29.8. Latest: 7.161.29.
Sources for CVE-2021-45721 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.38; from 7.0.0 (including), before 7.29.8. NVD record
JFrog range
JFrog: prior to version 7.29.8 and 6.23.38. JFrog advisory
CVE-2024-2247 published March 13, 2024

JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.

Medium6.1 CVSS 3.1 6.1, rated by NVD yes yes No fix on your branch; the nearest fix is 7.77.7. Latest: 7.161.29.
Sources for CVE-2024-2247 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): through 7.77.7. NVD record
JFrog range
JFrog: versions below 7.77.7, 7.82.1. JFrog advisory
CVE-2026-69107 published August 12, 2026

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

Medium5.9 CVSS 3.1 5.9, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.104.16. Latest: 7.161.29.
Sources for CVE-2026-69107 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.104.16; from 7.111.0 (including), before 7.111.14; from 7.117.0 (including), before 7.117.21; from 7.125.0 (including), before 7.125.14; from 7.133.0 (including), before 7.133.21; from 7.146.0 (including), before 7.146.8. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.104.16; from 7.111.0 before 7.111.14; from 7.117.0 before 7.117.21; from 7.125.0 before 7.125.14; from 7.133.0 before 7.133.21; from 7.146.0 before 7.146.8. JFrog advisory
CVE-2021-45074 published March 2, 2022

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

Medium5.4 CVSS 3.1 5.4, rated by NVD yes yes No fix on your branch; the nearest fix is 7.29.3. Latest: 7.161.29.
Sources for CVE-2021-45074 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.38; from 7.0.0 (including), before 7.29.3. NVD record
JFrog range
JFrog: before 7.29.3 and 6.23.38. JFrog advisory
CVE-2026-65922 published July 27, 2026

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.

Medium5.4 CVSS 3.1 5.4, rated by NVD yes yes No fix on your branch; the nearest fix is 7.111.18. Latest: 7.161.29.
Sources for CVE-2026-65922 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.111.18; from 7.117.0 (including), before 7.117.25; from 7.125.0 (including), before 7.125.18; from 7.133.0 (including), before 7.133.27; from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.111.18; from 7.117.0 before 7.117.25; from 7.125.0 before 7.125.18; from 7.133.0 before 7.133.27; from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-66376 published August 12, 2026

Credentials for a deleted user may remain valid for a short period under specific conditions.

Medium5.4 CVSS 3.1 5.4, rated by NVD yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66376 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66377 published August 12, 2026

An unauthenticated user may access restricted repository information under specific conditions.

Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66377 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66381 published August 12, 2026

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

Medium5.3 CVSS 3.1 5.3, rated by NVD yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66381 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66384 published August 12, 2026

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66384 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68753 published August 12, 2026

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68753 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68760 published August 12, 2026

An unauthenticated user may bypass authentication under specific cache conditions.

Medium5.3 CVSS 3.1 5.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68760 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2021-45730 published May 19, 2022

JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

Medium4.9 CVSS 3.1 4.9, rated by NVD yes yes No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29.
Sources for CVE-2021-45730 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 7.0.0 (including), before 7.31.10. NVD record
JFrog range
JFrog: prior to 7.31.10. JFrog advisory
CVE-2021-46687 published July 6, 2022

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

Medium4.9 CVSS 3.1 4.9, rated by NVD yes yes No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29.
Sources for CVE-2021-46687 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 6.0.0 (including), before 6.23.38; from 7.0.0 (including), before 7.31.10. NVD record
JFrog range
JFrog: prior to version 7.31.10 and 6.23.38. JFrog advisory
CVE-2024-3505 published April 15, 2024

JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

Medium4.3 CVSS 3.1 4.3, rated by NVD yes yes No fix on your branch; the nearest fix is 7.77.3. Latest: 7.161.29.
Sources for CVE-2024-3505 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.77.3. NVD record
JFrog range
JFrog: versions below 7.77.3. JFrog advisory
CVE-2026-66378 published August 12, 2026

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66378 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66379 published August 12, 2026

An authenticated user may view private Puppet module metadata without repository read access.

Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66379 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66380 published August 12, 2026

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66380 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-66382 published August 12, 2026

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-66382 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-68755 published August 12, 2026

A bundle writer may create misleading release promotion information under specific conditions.

Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) yes yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-68755 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): before 7.146.35; from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 0 before 7.146.35; from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-65926 published August 12, 2026

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

Low3.1 CVSS 3.1 3.1, rated by JFrog (CNA) no NVD data yes No fix on your branch; the nearest fix is 7.146.35. Latest: 7.161.29.
Sources for CVE-2026-65926 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Awaiting Analysis). NVD record
JFrog range
JFrog: versions when the bundle name. JFrog advisory
CVE-2021-46270 published March 2, 2022

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

Low2.7 CVSS 3.1 2.7, rated by NVD yes yes No fix on your branch; the nearest fix is 7.31.10. Latest: 7.161.29.
Sources for CVE-2021-46270 and 7.5.5
NVD range
NVD configuration (NVD status: Modified): from 7.0.0 (including), before 7.31.10. NVD record
JFrog range
JFrog: before 7.31.10. JFrog advisory
11 other JFrog Artifactory CVEs on record that do not affect 7.5.5

Each of these is fixed at or before 7.5.5 on its branch, or its published range does not include this version. The fix column shows the fix this version already carries.

JFrog Artifactory CVEs on record that do not affect 7.5.5
CVE-2026-70551 published August 25, 2026 High8.5 CVSS 3.1 8.5, rated by JFrog (CNA) no NVD data no This version predates the affected range (from 7.146.0).
Sources for CVE-2026-70551 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Awaiting Analysis). NVD record
JFrog range
JFrog's CVE record: from 7.146.0 before 7.146.36; from 7.161.0 before 7.161.19. JFrog advisory
CVE-2026-69105 published August 12, 2026 High8.1 CVSS 3.1 8.1, rated by JFrog (CNA) no no This version predates the affected range (from 7.161.0).
Sources for CVE-2026-69105 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-69104 published August 25, 2026 High7.6 CVSS 3.1 7.6, rated by JFrog (CNA) no NVD data no This version predates the affected range (from 7.161.0).
Sources for CVE-2026-69104 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Awaiting Analysis). NVD record
JFrog range
JFrog: versions address the issue.. JFrog advisory
CVE-2023-42509 published March 7, 2024 High7.5 CVSS 3.1 7.5, rated by NVD no no This version predates the affected range (from 7.17.4).
Sources for CVE-2023-42509 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.17.4 (including), before 7.77.0. NVD record
JFrog range
JFrog: version 7.17.4 but prior to version 7.77.0. JFrog advisory
CVE-2026-66015 published July 27, 2026 High7.2 CVSS 3.1 7.2, rated by JFrog (CNA) no no This version predates the affected range (from 7.146.0).
Sources for CVE-2026-66015 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2023-42662 published March 7, 2024 Medium6.5 CVSS 3.1 6.5, rated by NVD no no This version predates the affected range (from 7.59.0).
Sources for CVE-2023-42662 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.59.0 (including), before 7.59.18; from 7.63.5 (including), before 7.63.18; from 7.68.7 (including), before 7.68.19; from 7.71.2 (including), before 7.71.8. NVD record
JFrog range
JFrog: versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8. JFrog advisory
CVE-2026-66018 published July 27, 2026 Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) no no This version predates the affected range (from 7.146.0).
Sources for CVE-2026-66018 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.146.0 (including), before 7.146.34; from 7.161.0 (including), before 7.161.15. NVD record
JFrog range
JFrog's CVE record: from 7.146.0 before 7.146.34; from 7.161.0 before 7.161.15. JFrog advisory
CVE-2026-70550 published August 25, 2026 Medium6.5 CVSS 3.1 6.5, rated by JFrog (CNA) no NVD data no This version predates the affected range (from 7.146.0).
Sources for CVE-2026-70550 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Awaiting Analysis). NVD record
JFrog range
JFrog: versions.. JFrog advisory
CVE-2025-14830 published January 4, 2026 Medium4.9 CVSS 3.1 4.9, rated by JFrog (CNA) no NVD data no This version predates the affected range (from 7.94.0).
Sources for CVE-2025-14830 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Deferred). NVD record
JFrog range
JFrog's CVE record: from 7.94.0 before 7.117.10. JFrog advisory
CVE-2026-70547 published August 12, 2026 Medium4.3 CVSS 3.1 4.3, rated by JFrog (CNA) no no This version predates the affected range (from 7.161.0).
Sources for CVE-2026-70547 and 7.5.5
NVD range
NVD configuration (NVD status: Analyzed): from 7.161.0 (including), before 7.161.16. NVD record
JFrog range
JFrog's CVE record: from 7.161.0 before 7.161.16. JFrog advisory
CVE-2026-70548 published August 25, 2026 Low3.5 CVSS 3.1 3.5, rated by JFrog (CNA) no NVD data no This version predates the affected range (from 7.146.0).
Sources for CVE-2026-70548 and 7.5.5
NVD range
NVD has published no version configuration for this record (NVD status: Awaiting Analysis). NVD record
JFrog range
JFrog's CVE record: from 7.146.0 before 7.146.36; from 7.161.11 before 7.161.19. JFrog advisory

About this page and CloudRepo

CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.