Loading market data...
← Back to CVE feed

CVE-2026-70550

MEDIUM CVSS 6.5 View on NVD ↗

Description

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Aug 25, 2026 16:17 UTC Modified: Aug 25, 2026 16:17 UTC