Sceawere
Vulnerability Detail
CVE-2026-68752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Project Resource Manager Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 4h ago
- Vendor
- jfrog
- Product
- artifactory
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A Project Resource Manager may gain broader administrative privileges under specific conditions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-08-12T15:18:21.880Z",
"pubdate": "2026-08-12T15:18:21.880Z",
"executiveSummary": "This security analysis addresses a privilege escalation vulnerability involving the Project Resource Manager role, which may allow users assigned to this specific resource management function to acquire broader administrative privileges under defined conditions. The primary impact of this vulnerability is unauthorized authorization creep, potentially granting high-level administrative capabilities to lower-privileged accounts. The affected component is the Project Resource Manager role within the authorization and access control subsystem of the target platform. Risk implications include severe compromise of confidentiality, integrity, and availability, as attackers leveraging this flaw could execute administrative operations, modify critical system configurations, and access sensitive project data beyond their intended scope. Attacker capabilities rely on possessing or acquiring the initial Project Resource Manager role and satisfying the specific contextual conditions required to trigger the escalation pathway. Exploitation requirements mandate that the attacker operates within an environment where the requisite conditional triggers are met, allowing the access control mechanism to improperly elevate privileges during resource management operations.",
"technicalDetails": "The vulnerability stems from flaws in the access control logic governing the Project Resource Manager role. Specifically, the root cause lies in improper role-based access control (RBAC) enforcement and insufficient boundary validation when processing specific resource management workflows. Under precise operational conditions, the authorization engine fails to properly restrict the scope of the Project Resource Manager, incorrectly evaluating session permissions and granting broader administrative privileges to the executing security context.\nThe vulnerable component resides within the authorization subsystem responsible for mapping user roles to administrative capabilities. Exploitation of this vulnerability requires the attacker to authenticate as a user holding the Project Resource Manager role. While specific network exposure and authentication prerequisites depend on the underlying application architecture, the attack flow initiates when the user interacts with targeted resource management functions under the precise conditions required to trigger the privilege escalation flaw.\nDuring the attack sequence, the user initiates a sequence of resource management operations designed to manipulate the authorization state. The application processes these requests without adequately verifying whether the session context warrants the expansion of privileges. Consequently, the internal role evaluation mechanism improperly propagates administrative rights to the user session. Once the privilege escalation is successful, the post-exploitation impact allows the attacker to execute administrative-level commands, alter core system configurations, bypass security controls, and manage other privileged accounts or system resources, leading to a complete compromise of the affected environment."
}