Description
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user with read access to a JFrog Artifactory Cargo remote repository can cause Artifactory to request arbitrary URLs and return the response to the user. This use of the repository interface enables a Server‑Side Request Forgery that allows the attacker to discover internal network services, exfiltrate data, or proxy further attacks. The weakness is an input validation flaw, classified as CWE‑918.

Affected Systems

The affected product is JFrog Artifactory for self‑managed installations. No specific version ranges are disclosed; therefore any installation that grants read permissions on a Cargo remote repository may be vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. An EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalogue, implying no known public exploits. The likely attack vector is the web API that processes repository read requests; cloning or triggering a read operation provides the attacker with the ability to drive Artifactory to arbitrary destinations.

Generated by OpenCVE AI on August 3, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JFrog Artifactory to the latest release that contains the SSRF fix.
  • Restrict read access to the Cargo remote repository to trusted users or roles only and audit permissions regularly.
  • Limit Artifactory’s outbound connectivity through network segmentation or firewall rules to prevent it from accessing internal or sensitive endpoints.

Generated by OpenCVE AI on August 3, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Title Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-07-27T20:03:14.377Z

Reserved: 2026-07-23T13:34:38.372Z

Link: CVE-2026-65925

cve-icon Vulnrichment

Updated: 2026-07-27T20:03:07.616Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T20:16:41.677

Modified: 2026-07-30T14:45:18.260

Link: CVE-2026-65925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:00:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)