Description
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
Published: 2026-08-12
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an anonymous or low‑privilege authenticated user to discover the names and versions of private Release Bundles when the bundle name is already known. This results in the disclosure of potentially confidential metadata, compromising the confidentiality of the released artifacts. The weakness is a missing authorization check, classified as CWE‑862.

Affected Systems

Affected product is JFrog Artifactory, specifically the self‑managed release bundles component. No specific version information is listed in the CNA data, so all generally released Artifactory instances that expose private release bundles with anonymous or low‑privilege access are potentially impacted.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity. With EPSS not available and the vulnerability not listed in CISA KEV, the likelihood of widespread exploitation appears modest, yet the information disclosed could be valuable to an attacker. Without the bundle name, the flaw offers minimal direct impact, but once an attacker knows a bundle name they can enumerate its version. Attackers could reach the endpoint via any exposed Artifactory instance that permits anonymous or low‑privilege access.

Generated by OpenCVE AI on August 12, 2026 at 23:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that removes the missing authorization check.
  • Disable anonymous access or restrict it to read‑only resources for private Release Bundles.
  • Enforce role‑based access control so only authorized users can retrieve Release Bundle metadata.
  • Monitor access logs for anomalous enumeration attempts.

Generated by OpenCVE AI on August 12, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
Title Private Release Bundle versions may be disclosed under specific configurations
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-12T18:41:54.602Z

Reserved: 2026-07-23T13:34:38.372Z

Link: CVE-2026-65926

cve-icon Vulnrichment

Updated: 2026-08-12T18:41:51.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T16:17:13.393

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-65926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses