Skip to content
JFrogCVE-2026-69105

JFrog artifactory: insufficient authenticity check

High8.1CVE-2026-69105 · Published Aug 12, 2026 · updated Sep 11, 2026

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
>= 7.161.0, < 7.161.167.161.16
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: improper input validation
High8.8Aug 12
JFrog artifactory: improper authentication
High7.5Aug 12
JFrog artifactory: missing authorization
Medium4.3Aug 12
JFrog artifactory: missing authorization
Medium5.9Aug 12
JFrog artifactory: improper signature check
High7.2Aug 12
JFrog artifactory: missing authorization
Medium6.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.