CVE-2026-70551

8.5

JFrog · Artifactory

A Server-Side Request Forgery (SSRF) vulnerability in JFrog Artifactory allows authenticated users to manipulate VCS repository configurations and data URLs.

Executive summary

An authenticated Server-Side Request Forgery vulnerability in JFrog Artifactory allows low-privileged users to potentially access sensitive internal resources or perform unauthorized network requests.

Vulnerability

This is a Server-Side Request Forgery (CWE-918) vulnerability where an authenticated user with read access to a remote VCS repository can replace the configured origin or supply an absolute VCS data URL to force the server to initiate unintended network requests.

Business impact

The vulnerability carries a CVSS score of 8.5, indicating a high severity risk. Successful exploitation could allow an attacker to pivot into internal networks, scan private infrastructure, or access metadata and configuration files that are otherwise inaccessible, leading to potential data exfiltration or service disruption.

Remediation

Immediate Action: Update JFrog Artifactory instances to version 7.161.19, 7.146.36, or the latest available maintenance release provided by the vendor.

Proactive Monitoring: Review access logs for unusual repository configuration changes or unexpected outbound network connections originating from the Artifactory server.

Compensating Controls: Implement strict egress filtering on the Artifactory host to restrict communication to known, trusted VCS endpoints and block access to internal private IP ranges.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for internal network exposure, organizations should prioritize patching affected Artifactory installations. Immediate application of the vendor-supplied updates is the only effective way to neutralize the underlying logic flaw.

More JFrog CVEs