SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65925

MEDIUM · CVSS 6.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

JFrog Artifactory is vulnerable to unauthorized access, allowing users with read permissions on the Cargo remote repository to make requests to unintended URLs and retrieve their responses. This could lead to information disclosure or exposure of sensitive data. Organizations using JFrog Artifactory should prioritize this issue to mitigate potential data leaks and ensure secure repository management.

CVE
CVE-2026-65925
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%

Original NVD Description

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Related CVEs

Other vulnerabilities affecting the same vendor(s)