What is CVE-2026-65924?
CVE-2026-65924 is a Server-Side Request Forgery (SSRF) vulnerability in JFrog Artifactory's support for Terraform remote repositories. An authenticated user, or an unauthenticated user if anonymous access is enabled, could force Artifactory to make outbound HTTP requests to arbitrary destinations. Updating to the latest version is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-65924 JFrog Artifactory-də Terraform remote reposuna aid Server-Side Request Forgery (SSRF) zəifliyidir. Autentifikasiyalı, yaxud anonim giriş aktivdirsə qeyri-autentifikasiyalı istifadəçi Artifactory-nin ixtiyari xarici HTTP sorğuları göndərməsinə səbəb ola bilər. Bu zəiflikdən qorunmaq üçün məhsulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: JFrog
FAQ2
Does exploiting CVE-2026-65924 in JFrog Artifactory require authentication?
No, an unauthenticated user can exploit this SSRF vulnerability if anonymous access is enabled.
What measure is recommended to mitigate CVE-2026-65924?
Updating to the latest version is recommended to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.