PT-2026-81333 · Jfrog · Artifactory

CVE-2026-70551

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions JFrog Artifactory versions prior to 7.161.19 JFrog Artifactory versions prior to 7.146.36
Description An authenticated user with permissions to read an existing remote Version Control System (VCS) repository can trigger server-side requests. This occurs when a user replaces the configured origin or provides an absolute VCS data URL, leading to Server-Side Request Forgery (SSRF), a condition where the server is coerced into making unauthorized requests to internal or external resources.
Recommendations Upgrade to version 7.161.19. Upgrade to version 7.146.36.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70551

Affected Products

Artifactory