JFrogCVE-2026-69104
JFrog artifactory: information disclosure
High7.6CVE-2026-69104 · Published Aug 25, 2026 · updated Aug 28, 2026
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| artifactory Product | >= 7.161.0, < 7.161.19 | 7.161.19 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More JFrog advisories
All JFrog| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | JFrog artifactory: improper authentication | Critical9.8 | 7.111.21+3 more |
| Aug 25 | JFrog artifactory: server-side request forgery | Low3.5 | 7.161.19+1 more |
| Aug 25 | JFrog artifactory: missing authorization | Medium6.5 | 7.161.19+1 more |
| Aug 25 | JFrog artifactory: server-side request forgery | High8.5 | 7.161.19+1 more |
| Aug 12 | JFrog artifactory: improper input validation | High8.8 | 7.146.28 |
| Aug 12 | JFrog artifactory: improper authentication | High7.5 | 7.111.20+3 more |