CVE-2026-42017: JFrog Artifactory
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
Affected products
- JFrog Artifactory: before 7.133.21 (fixed in 7.133.21); from 7.146.0, before 7.146.8 (fixed in 7.146.8)
Published 2026-07-27. Last modified 2026-07-30.