CVE-2026-65923
Potential server-side request forgery in Artifactory Ansible repository handling
Description
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
In plain language
AI Act nowCVE-2026-65923 is a JFrog Artifactory flaw where a user with limited repository access may trick the server into making unintended web requests, potentially exposing or changing sensitive data; if you run Artifactory and allow Ansible repository features, you should act now.
In JFrog Artifactory (CVE-2026-65923), an input validation weakness (CWE-918) in Ansible repository handling can enable a user—under specific repository access conditions—to trigger server-side request forgery (SSRF) that leads to unintended outbound requests, with demonstrated real-world exploitation reported during an internal test.
What to do now
- Check your JFrog Artifactory version and whether you use/enable Ansible repository handling.
- Confirm whether any users or automation can create or manipulate Ansible repositories or repository-related inputs (the attack requires low authentication and specific repository access conditions).
- Upgrade Artifactory to one of the fixed versions: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, or 7.161.15.
- After upgrading, review server logs for unusual outbound requests or denied/blocked attempts related to repository handling.
- If you cannot upgrade immediately, restrict who can access Ansible repositories and remove unnecessary repository permissions until you can patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- JFrog Zero-Days Exploited in OpenAI-Hugging Face Hacken-us·SecurityWeek· Exploited Artifactory zero-day
- JFrog tries to spin OpenAI 0-day exploit of its app into a success storyen·Ars Technica (Security)· Exploited Artifactory zero-day
- OpenAI models used Artifactory zero-days to escape to the interneten-us·BleepingComputer· Exploited Artifactory zero-day
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachen·The Hacker News· Exploited Artifactory zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65923 and every CVE in our database. Create a free account — no credit card required.
Create Free Account