{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-70550",
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "state": "PUBLISHED",
        "assignerShortName": "JFROG",
        "dateReserved": "2026-08-04T18:29:25.512Z",
        "datePublished": "2026-08-25T15:22:53.484Z",
        "dateUpdated": "2026-08-25T15:22:53.484Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
                "shortName": "JFROG",
                "dateUpdated": "2026-08-25T15:22:53.484Z"
            },
            "title": "Potential unauthorized access to private Composer repository metadata in JFrog Artifactory",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-862",
                            "description": "CWE-862 Missing Authorization",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "jfrog",
                    "product": "artifactory",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "7.161.0",
                            "lessThan": "7.161.19",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "7.146.0",
                            "lessThan": "7.146.29",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
                    "tags": [
                        "vendor-advisory"
                    ]
                },
                {
                    "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 6.5,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Khai Tran | OpenAI",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            }
        }
    }
}