Incorrect authorization in Artifactory - CVE-2026-68755
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to create misleading release-promotion information.
The vulnerability exists due to incorrect authorization in bundle writers when creating release-promotion information under specific conditions. A remote user can create crafted bundle-related release information to create misleading release-promotion information.