CVE-2026-70547: Potential unauthorized metadata exposure in JFrog Artifactory
Published Aug 12, 2026
·Updated
An authenticated user without repository read permission may access package metadata under specific conditions.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 12, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-70547?
CVE-2026-70547 has a medium severity rating of 4.3.
2
How does CVE-2026-70547 affect JFrog Artifactory?
CVE-2026-70547 may allow an authenticated user without repository read permission to access package metadata.
3
What are the conditions for CVE-2026-70547 to be exploited?
The vulnerability occurs under specific conditions that allow unauthorized access to metadata by an authenticated user.
4
How do I fix CVE-2026-70547?
To mitigate CVE-2026-70547, ensure that repository permissions are correctly configured for authenticated users.
5
When was CVE-2026-70547 published?
CVE-2026-70547 was published on August 12, 2026.