Sceawere

Vulnerability Detail

CVE-2026-69107UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JFrog Artifactory Artifact Access Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
3h ago
Vendor
jfrog
Product
artifactory
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-12T16:17:20.220Z",
  "pubdate": "2026-08-12T16:17:20.220Z",
  "executiveSummary": "An access control vulnerability has been identified in JFrog Artifactory, allowing unauthenticated users to gain unauthorized access to restricted artifacts under specific operational conditions.\nThe vulnerability exposes sensitive organizational assets stored within the repository management system, potentially leading to unauthorized data exfiltration, intellectual property theft, or the exposure of proprietary binaries and configuration files.\nThe affected system is JFrog Artifactory, where improper permission enforcement mechanisms fail to adequately restrict object retrieval based on authentication states.\nThe risk implications are severe, as malicious actors can harvest sensitive internal artifacts without requiring valid user credentials or prior system access.\nThe attacker capabilities are limited to unauthenticated network access, allowing remote exploitation if network boundaries permit communication with the vulnerable Artifactory instance.\nExploitation specifically requires the targeted Artifactory server to be configured under the precise conditions that trigger the access control bypass, though detailed prerequisites beyond the lack of authentication are bound to the specific configuration state of the deployment.",
  "technicalDetails": "The root cause of the vulnerability stems from a flaw in the authorization logic of JFrog Artifactory, specifically concerning how access control lists or permission targets evaluate requests for restricted artifacts.\nUnder specific deployment and configuration conditions, the application fails to enforce authentication checks or validate authorization tokens prior to serving requested repository items.\nThe vulnerable component resides within the artifact retrieval and request handling subsystem of JFrog Artifactory.\nThe exploitation method relies on crafting direct HTTP/HTTPS requests to target endpoints associated with restricted artifacts, bypassing the expected authentication gateway or permission validation routines.\nThe attack flow begins with the unauthenticated actor identifying or guessing paths to restricted artifacts or leveraging reconnaissance to locate sensitive repositories within the Artifactory instance.\nUpon formulating the request, the client transmits the payload over the network to the vulnerable Artifactory service.\nBecause the internal authorization checks improperly handle the request context under the specific conditions, the application processes the retrieval command as if it originated from an authorized entity.\nThe server subsequently reads the requested artifact from the underlying storage mechanism and streams the payload back to the unauthenticated client in the HTTP response body.\nThe network exposure is remote, typically accessible over standard HTTP or HTTPS protocols depending on the front-end server configuration of the Artifactory deployment.\nNo authentication requirements or privilege requirements are needed by the adversary to execute this attack, as the vulnerability explicitly permits unauthenticated access.\nThe post-exploitation impact includes the unauthorized disclosure of sensitive software packages, build artifacts, dependencies, and internal enterprise assets, which may facilitate subsequent supply chain attacks or further compromise of connected infrastructure."
}
CVE-2026-69107: JFrog Artifactory Artifact Access Vulnerability (MEDIUM Severity, CVSS: 5.9) - Sceawere