Deserialization of Untrusted Data in Artifactory - CVE-2026-68756
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to affect Artifactory session handling.
The vulnerability exists due to deserialization of untrusted data in stored session data handling when processing stored session data. A remote user can modify stored session data to affect Artifactory session handling.
Exploitation requires write access to stored session data and only occurs under specific conditions.