SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65924

MEDIUM · CVSS 6.5 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

JFrog Artifactory's support for Terraform remote repositories is vulnerable to Server-Side Request Forgery (SSRF), allowing both authenticated and potentially unauthenticated users to manipulate the application into making outbound HTTP requests to arbitrary destinations. This could lead to unauthorized access to sensitive data or services within the network. Organizations using JFrog Artifactory, particularly those with enabled anonymous access, should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-65924
Severity
MEDIUM
CVSS
6.5
EPSS
0.38%

Original NVD Description

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.

Related CVEs

Other vulnerabilities affecting the same vendor(s)