CVE-2026-65926: JFrog Artifactory

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

Affected products

  • JFrog Artifactory: before 7.146.35 (fixed in 7.146.35); from 7.161.0, before 7.161.16 (fixed in 7.161.16)

Published 2026-08-12. Last modified 2026-08-28.