SB2026083190 - Multiple vulnerabilities in JFrog Artifactory
Published: August 31, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 22 vulnerabilities.
1) Path traversal (CVE-ID: CVE-2026-66381)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access content outside configured upstream paths.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in repository access controls when handling repository content requests. A remote user can request content outside a configured upstream path to access content outside configured upstream paths.
Exploitation requires repository read access together with cache-deploy permission.
2) Path traversal (CVE-ID: CVE-2026-66382)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write files outside the intended work directory.
The vulnerability exists due to path traversal in file write handling when processing authenticated file write operations. A remote user can submit a crafted pathname to write files outside the intended work directory.
3) Missing Authorization (CVE-ID: CVE-2026-66380)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in OCI referrer metadata access control when handling requests for private OCI referrer metadata. A remote user can send a request for private OCI referrer metadata to disclose sensitive information.
The issue affects authenticated users who do not have repository read permission.
4) Missing Authorization (CVE-ID: CVE-2026-66378)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in private NuGet metadata access controls when handling requests for repository metadata. A remote user can request private NuGet metadata without repository read permission to disclose sensitive information.
5) Improper Authentication (CVE-ID: CVE-2026-68760)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in remember-me authentication when specific cache conditions are present. A remote attacker can exploit the authentication flow to bypass authentication.
6) Missing Authorization (CVE-ID: CVE-2026-65926)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in Release Bundle version disclosure functionality when querying for a known bundle name. A remote user can query for a known bundle name to disclose sensitive information.
The issue may expose private Release Bundle names and versions.
7) Cleartext storage of sensitive information (CVE-ID: CVE-2026-66016)
CWE-ID: CWE-312 - Cleartext Storage of Sensitive Information
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in rendered Helm manifests when generating TLS private keys. A local privileged user can read rendered manifests to disclose sensitive information.
8) Missing Authorization (CVE-ID: CVE-2026-66375)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to remove protected internal metadata across repositories.
The vulnerability exists due to missing authorization in metadata protection mechanisms when handling authenticated repository operations. A remote user can delete protected internal metadata to remove protected internal metadata across repositories.
9) Path traversal (CVE-ID: CVE-2026-66384) Exploited
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write data outside the intended Docker cache path.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the Docker cache path handling for remote repositories when processing authenticated operations under specific remote-repository conditions. A remote user can write crafted data to cause writes outside the intended Docker cache path.
Only authenticated access and specific remote-repository conditions are required for exploitation.
10) Insufficient verification of data authenticity (CVE-ID: CVE-2026-69105)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and compromise artifact integrity.
The vulnerability exists due to insufficient verification of data authenticity in the package cache when caching package content. A remote attacker can cause untrusted package content to be cached to cause a denial of service and compromise artifact integrity.
11) Missing Authorization (CVE-ID: CVE-2026-70547)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose package metadata.
The vulnerability exists due to missing authorization in repository metadata access controls when handling metadata requests. A remote user can request package metadata without repository read permission to disclose package metadata.
12) Missing Authorization (CVE-ID: CVE-2026-66377)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose restricted repository information.
The vulnerability exists due to missing authorization in repository information access controls when handling requests under specific conditions. A remote attacker can send a request to disclose restricted repository information.
13) Missing Authorization (CVE-ID: CVE-2026-66379)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Puppet module metadata access functionality when handling requests for private Puppet module metadata. A remote user can request metadata for a private Puppet module without repository read access to disclose sensitive information.
14) Missing Authorization (CVE-ID: CVE-2026-68758)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose restricted support information.
The vulnerability exists due to missing authorization in support information access controls when handling authenticated requests under specific conditions. A remote user can access restricted support information to disclose restricted support information.
15) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-68759)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to impersonate other users.
The vulnerability exists due to improper verification of cryptographic signature in the integration credential handling mechanism when processing valid integration credentials under specific conditions. A remote user can use a valid integration credential to impersonate other users.
16) Missing Authorization (CVE-ID: CVE-2026-68753)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access restricted content.
The vulnerability exists due to missing authorization in credentialed remote repository access controls when handling anonymous requests under a specific repository configuration. A remote attacker can send crafted requests to access restricted content.
Exploitation requires a credentialed remote repository to be configured in a specific way.
17) Incorrect authorization (CVE-ID: CVE-2026-68755)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create misleading release-promotion information.
The vulnerability exists due to incorrect authorization in bundle writers when creating release-promotion information under specific conditions. A remote user can create crafted bundle-related release information to create misleading release-promotion information.
18) Improper privilege management (CVE-ID: CVE-2026-68752)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in project resource manager role handling when accessing administrative functionality under specific conditions. A remote user can leverage project resource manager access to escalate privileges.
19) Deserialization of Untrusted Data (CVE-ID: CVE-2026-68756)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to affect Artifactory session handling.
The vulnerability exists due to deserialization of untrusted data in stored session data handling when processing stored session data. A remote user can modify stored session data to affect Artifactory session handling.
Exploitation requires write access to stored session data and only occurs under specific conditions.
20) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-68757)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to impersonate another user.
The vulnerability exists due to improper verification of cryptographic signature in the SAML authentication implementation when processing a valid SAML response under specific conditions. A remote user can reuse a valid SAML response to impersonate another user.
21) Missing Authorization (CVE-ID: CVE-2026-68754)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify protected package content.
The vulnerability exists due to missing authorization in docker layer information handling when processing package publishing operations. A remote user can overwrite docker layer information to modify protected package content.
22) Insufficient Session Expiration (CVE-ID: CVE-2026-66376)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to retain access after account deletion.
The vulnerability exists due to insufficient session expiration in user session handling when processing requests after a user account has been deleted. A remote user can continue using previously valid credentials to retain access after account deletion.
This occurs only for a short period under specific conditions.
Remediation
Install update from vendor's website.
References
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66381---repository-readers-may-access-content-outside-configured-upstream-paths
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66382---authenticated-users-may-write-files-outside-the-intended-work-directory
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66380---authenticated-users-may-access-private-oci-referrer-metadata
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66378---authenticated-users-may-access-private-nuget-metadata
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68760---potential-remember-me-authentication-bypass
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-65926---private-release-bundle-versions-may-be-disclosed
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66016---rendered-helm-manifests-may-contain-generated-tls-private-keys
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66375---low-privilege-users-may-remove-protected-artifactory-metadata
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66384---authenticated-users-may-write-data-outside-the-intended-docker-cache-path
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-69105---potential-package-cache-integrity-issue
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-70547---potential-unauthorized-metadata-exposure
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66377---anonymous-users-may-access-restricted-repository-information
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66379---authenticated-users-may-view-private-puppet-module-metadata
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68758---authenticated-users-may-access-restricted-support-information
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68759---integration-credential-holders-may-impersonate-users
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68753---anonymous-users-may-access-restricted-content-under-specific-configurations
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68755---bundle-writers-may-alter-trusted-release-information
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68752---project-resource-managers-may-escalate-privileges
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68756---potential-insecure-deserialization-in-jfrog-artifactory
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68757---potential-improper-saml-signature-verification
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-68754---publishers-without-delete-permission-can-overwrite-docker-layer-information
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-66376---deleted-users-may-temporarily-retain-access