NCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory. - Er is een privilege-escalatie mogelijk doordat het systeem de scope van tokens niet controleert, waardoor een aanvaller zijn rechten kan verhogen. - Daarnaast kunnen gebruikers met beperkte rechten toegang krijgen tot geprivilegieerde autorisatiematerialen en kunnen zij via een zwakke refresh token validatie een administrator token verkrijgen. - Verder is er een deserialisatieprobleem in de package handling, wat kan leiden tot ongeautoriseerde code-uitvoering of datamanipulatie. - Onjuiste URL-validatie maakt het mogelijk om ongeautoriseerde verzoeken te maken en interne services of gecachte data te benaderen. - Een path traversal kwetsbaarheid kan leiden tot het schrijven van bestanden buiten de bedoelde directory. - Er is ook een autorisatiezwakte in de metadata handling, waardoor gebruikers met beperkte rechten metadata kunnen wijzigen. - Specifieke componenten zoals de Ansible repository, Terraform remote repositories en Cargo remote repository zijn kwetsbaar voor Server-Side Request Forgery (SSRF) aanvallen, waarbij ongewenste HTTP-verzoeken kunnen worden uitgevoerd en de reacties daarvan kunnen worden ingezien. - Verder is er een kwetsbaarheid in het interne authenticatiesysteem die privilege-escalatie mogelijk maakt. - Ten slotte kunnen gebruikers met leesrechten op een repository ook omgevingsvariabelen van andere repositories inzien, wat kan leiden tot blootstelling van vertrouwelijke build secrets. OpenAI heeft in een publieke blog-post vermeld dat hierboven beschreven kwetsbaarheden als ZeroDay kwetsbaarheid zijn misbruikt door een OpenAI model om zelfstandig toegang te krijgen tot het internet en daarmee in staat te zijn geweest een derde partij aan te vallen. OpenAI heeft JFrog onmiddellijk in kennis gesteld zodat JFrog de kwetsbaarheden zo spoedig mogelijk kon verhelpen.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0272
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-420160.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-420170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-656160.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-656170.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-656180.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-659210.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-659220.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-659230.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-659240.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-659250.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42016 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42017 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65616 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65617 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65618 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65921 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65922 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65923 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65924 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65925 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66014 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66015 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66018 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] JFrog Artifactory: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-66018: Build readers can access another repository's environment properties. A caller with read acces…nvd
- highCVE-2026-66015: An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under a…nvd
- highCVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal request processing …nvd
- mediumCVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory reque…nvd
- mediumCVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Ser…nvd
- mediumCVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,…nvd
- highCVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user w…nvd
- highCVE-2026-65921: A path validation weakness in archive extraction/write handling allows entries with traversal …nvd
- mediumCVE-2026-65618: Improper URL validation when handling specific URLs, allows an attacker, under certain conditi…nvd
- highCVE-2026-65617: A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged …nvd
- highCVE-2026-65616: Incorrect authorization validation in refresh token signature allows non-admin users to obtain…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classicncsc-nl · 2026-07-31
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30
- unknownNCSC-2026-0269 [1.01] [M/H] Vulnerabilities fixed in VMware products2026-07-29