CVE-2026-70550 - Potential unauthorized access to private Composer repository metadata in JFrog Artifactory
CVE ID :CVE-2026-70550
Published : Aug. 25, 2026, 3:22 p.m. | 1 hour, 6 minutes ago
Description :An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 25, 2026, 3:22 p.m. | 1 hour, 6 minutes ago
Description :An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...