Skip to content
JFrogCVE-2026-69104

JFrog artifactory: information disclosure

High7.6CVE-2026-69104 · Published Aug 25, 2026 · updated Aug 28, 2026

An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
>= 7.161.0, < 7.161.197.161.19
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: improper authentication
Critical9.8Aug 28
JFrog artifactory: server-side request forgery
Low3.5Aug 25
JFrog artifactory: missing authorization
Medium6.5Aug 25
JFrog artifactory: server-side request forgery
High8.5Aug 25
JFrog artifactory: improper input validation
High8.8Aug 12
JFrog artifactory: improper authentication
High7.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.