Missing Authorization in JFrog Artifactory - CVE-2026-70550
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in Composer repository handling when processing requests for package metadata. A remote user can request metadata from repositories they are not authorized to read to disclose sensitive information.
Exploitation is possible only under specific conditions.