Description
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
Published: 2026-08-25
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a user with read access to a remote VCS repository to replace the repository’s origin or supply an absolute VCS data URL. This manipulation enables the artifact manager to issue HTTP requests to arbitrary destinations, constituting a Server‑Side Request Forgery. The impact can include unauthorized data access, potential exposure of internal network resources, and in worst‑case scenarios, execution of unintended commands or code on the Artifactory host. The weakness is classified as CWE‑918.

Affected Systems

The affected product is JFrog Artifactory, a self‑managed binary repository manager. No specific version information is disclosed in the advisory, so all installations of the product should be reviewed for updates.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score is not available, and the issue is not present in the CISA KEV catalog. The likely exploit path requires a user who can read the remote VCS repository, which suggests that attackers with legitimate read privileges can trigger the SSRF. Due to the lack of a known exploit in public feeds, the likelihood of exploitation is uncertain, but the high severity warrants timely remediation.

Generated by OpenCVE AI on August 25, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JFrog Artifactory to a version that contains the fix for the SSRF flaw in VCS remote download.
  • Restrict read access on VCS repositories to only trusted users, enforcing least privilege.
  • If remote VCS repository support is not required, disable the feature or enforce a whitelist of acceptable VCS origins to prevent arbitrary URL configuration.

Generated by OpenCVE AI on August 25, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Tue, 25 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
Title Server-Side Request Forgery Via VCS remote download in JFrog Artifactory
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-26T19:47:41.387Z

Reserved: 2026-08-04T18:29:25.512Z

Link: CVE-2026-70551

cve-icon Vulnrichment

Updated: 2026-08-26T19:47:35.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T15:16:38.060

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-70551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T17:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)