Missing Authorization in JFrog Artifactory - CVE-2026-69107
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose restricted artifacts.
The vulnerability exists due to missing authorization in artifact access controls when handling requests for restricted artifacts under specific conditions. A remote attacker can send a crafted request to disclose restricted artifacts.
Exploitation is possible without authentication only under specific conditions.