CVE-2026-70551: Server-Side Request Forgery Via VCS remote download in JFrog Artifactory
Published Aug 25, 2026
·Updated
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 25, 2026
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs permission to read an existing remote VCS repository. They can then replace the repository's configured origin or provide an absolute VCS data URL.
2
What access does exploitation provide?
The issue can cause server-side requests through Artifactory. The supplied data does not specify which internal or external destinations are reachable, or what response data an attacker can retrieve.
3
Are default configurations affected?
The available information does not state whether remote VCS repositories are configured by default. Exposure depends on having an existing remote VCS repository and allowing a user with read access to alter its origin or provide an absolute VCS data URL.