NCSC-2026-0272 [1.00] [M/H] Vulnerabilities patched in JFrog Artifactory
JFrog has patched multiple vulnerabilities in JFrog Artifactory. The vulnerabilities concern various components of JFrog Artifactory. - There is a possibility of privilege escalation because the system does not check the scope of tokens, allowing an attacker to elevate their rights. - Additionally, users with limited rights can gain access to privileged authorization materials and can obtain an administrator token through weak refresh token validation. - Further, there is a deserialization issue in the package handling that can lead to unauthorized code execution or data manipulation. - Improper URL validation makes it possible to make unauthorized requests and access internal services or cached data. - A path traversal vulnerability can lead to writing files outside the intended directory. - There is also an authorization weakness in metadata handling, allowing users with limited rights to modify metadata. - Specific components such as the Ansible repository, Terraform remote repositories, and Cargo remote repository are vulnerable to Server-Side Request Forgery (SSRF) attacks, where undesired HTTP requests can be executed and their responses viewed. - Further, there is a vulnerability in the internal authentication system that enables privilege escalation. - Finally, users with read rights on a repository can also view environment variables of other repositories, which can lead to exposure of confidential build secrets. OpenAI mentioned in a public blog post that the vulnerabilities described above were exploited as ZeroDay vulnerabilities by an OpenAI model to independently gain access to the internet and thereby be able to attack a third party. OpenAI immediately notified JFrog so that JFrog could patch the vulnerabilities as quickly as possible.
CSIRTS triage
- What
- Multiple vulnerabilities including token scope bypass allowing privilege escalation, weak refresh token validation exposing admin tokens, deserialization flaws enabling code execution, improper URL validation allowing unauthorized service access, path traversal enabling writes outside intended directories, and authorization weaknesses in metadata handling.
- Who is affected
- All deployments of JFrog Artifactory with standard configurations are affected.
- Urgency
- High; multiple critical flaws including RCE and privilege escalation require immediate patching.
- Action
- Apply JFrog Artifactory security patches immediately as released by vendor.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Artifactory
Get an email when a new Artifactory advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0272
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-420160.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-420170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656160.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656170.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656180.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659210.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659220.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659230.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659240.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659250.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42016 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42017 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65616 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65617 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65618 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65921 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65922 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65923 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65924 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65925 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66014 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66015 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66018 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] JFrog Artifactory: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-66018: Build readers can access another repository's environment properties. A caller with read acces…nvd
- highCVE-2026-66015: An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under a…nvd
- highCVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal request processing …nvd
- mediumCVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory reque…nvd
- mediumCVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Ser…nvd
- mediumCVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,…nvd
- highCVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user w…nvd
- highCVE-2026-65921: A path validation weakness in archive extraction/write handling allows entries with traversal …nvd
- mediumCVE-2026-65618: Improper URL validation when handling specific URLs, allows an attacker, under certain conditi…nvd
- highCVE-2026-65617: A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged …nvd
- highCVE-2026-65616: Incorrect authorization validation in refresh token signature allows non-admin users to obtain…nvd
Recent advisories for JFrog Artifactory
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] JFrog Artifactory: Multiple vulnerabilitiescert-bund · 2026-07-28
- highCVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal request processing …nvd · 2026-07-27
- mediumCVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory reque…nvd · 2026-07-27
- mediumCVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Ser…nvd · 2026-07-27
- mediumCVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,…nvd · 2026-07-27
- highCVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user w…nvd · 2026-07-27
More from NCSC-NL Advisories
- unknownNCSC-2026-0279 [1.00] [M/H] Vulnerabilities patched in Cisco IOS XE Software2026-08-07
- unknownNCSC-2026-0275 [1.01] [M/H] Vulnerabilities patched in N-able N-central2026-08-07
- unknownNCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic2026-08-06
- unknownNCSC-2026-0277 [1.00] [M/H] Vulnerabilities patched in Cisco Catalyst SD-WAN2026-08-06
- unknownNCSC-2026-0276 [1.00] [M/H] Vulnerabilities patched in Veeam Service Provider Console2026-08-05