CVE-2026-70550: Potential unauthorized access to private Composer repository metadata in JFrog Artifactory
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to JFrog Artifactory and have at least low-level privileges. Exploitation also depends on the specific conditions in Artifactory's Composer repository handling.
What information could be exposed?
The issue may expose package metadata from Composer repositories that the authenticated user is not authorized to read. The described impact is confidentiality only; no integrity or availability impact is stated.
How should teams remediate the issue?
Upgrade to a fixed JFrog Artifactory version. The provided data confirms that fixed versions are available but does not identify the affected or fixed version numbers.