CVE-2026-70550
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Aug 25, 2026
Vendor
unknown
Description
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.