# JFrog Artifactory patches multiple vulnerabilities

Published: 2026-09-01 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/b8133cf9-89de-5eac-8b47-f6a43d8d0096/jfrog-artifactory-patches-multiple-vulnerabilities

> CERT-FR advisory details five JFrog Artifactory vulnerabilities including SSRF, security bypass, and potential admin auth bypass; patches available.

CERT-FR published an advisory covering multiple vulnerabilities in JFrog Artifactory affecting several release branches (7.111.4-7.111.x, 7.117.x, 7.125.x, 7.133.x, 7.146.x, and 7.161.x prior to their respective fixed versions). The issues, tracked as CVE-2026-69104, CVE-2026-70548, CVE-2026-70550, CVE-2026-70551, and CVE-2026-82329, collectively allow an attacker to compromise data confidentiality, perform server-side request forgery (SSRF), and bypass security policy controls. Notably, CVE-2026-82329 concerns a potential authentication bypass leading to administrative access, and CVE-2026-70548 relates to SSRF via CocoaPods external dependency handling; other flaws touch unauthorized repository migration and unauthorized access to private Composer repository metadata.

No indication of active in-the-wild exploitation is provided in the advisory. Organizations running affected Artifactory versions should consult the JFrog security bulletins referenced in the advisory and apply the vendor-supplied fixes for the impacted version branches promptly, particularly given the administrative access bypass risk associated with CVE-2026-82329.

## Mentioned in this report

- Vulnerabilities: CVE-2026-69104, CVE-2026-70548, CVE-2026-70550, CVE-2026-70551, CVE-2026-82329 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1100

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b8133cf9-89de-5eac-8b47-f6a43d8d0096/jfrog-artifactory-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
