Missing Authorization in Artifactory - CVE-2026-68753
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to access restricted content.
The vulnerability exists due to missing authorization in credentialed remote repository access controls when handling anonymous requests under a specific repository configuration. A remote attacker can send crafted requests to access restricted content.
Exploitation requires a credentialed remote repository to be configured in a specific way.