CVE-2026-70551: JFrog Artifactory

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

Affected products

  • JFrog Artifactory: from 7.161.0, before 7.161.19 (fixed in 7.161.19); from 7.146.0, before 7.146.36 (fixed in 7.146.36)

Published 2026-08-25. Last modified 2026-08-28.