Description
A Project Resource Manager may gain broader administrative privileges under specific conditions.
Published: 2026-08-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a Project Resource Manager to acquire broader administrative rights under specific conditions, creating a privilege escalation risk for the Artifactory instance. The weakness is categorized as CWE‑269, which indicates improper authorization. This escalation could enable the attacker to alter or delete repositories, create new users, or modify security settings, potentially compromising the confidentiality, integrity, and availability of the system.

Affected Systems

JFrog Artifactory is affected. No specific product versions were listed in the public information; impacted releases cannot be identified without further version data from the vendor documentation.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. EPSS was not reported, and the vulnerability is not listed in CISA’s KEV catalog, meaning the likelihood of known exploitation is uncertain. The attack vector is inferred to require the attacker to possess a Project Resource Manager role and identify the precise conditions that trigger privilege elevation; it is not explicitly disclosed in the advisory.

Generated by OpenCVE AI on August 13, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the exact Artifactory version from the installed instance or release notes.
  • Apply any security patches or updates provided by JFrog that address privilege escalation for Artifactory.
  • Restrict Project Resource Manager permissions to the minimal set required for their responsibilities and audit role assignments regularly.

Generated by OpenCVE AI on August 13, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A Project Resource Manager may gain broader administrative privileges under specific conditions.
Title Project Resource Managers may escalate privileges in JFrog Artifactory
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-13T13:21:16.855Z

Reserved: 2026-07-31T13:38:38.864Z

Link: CVE-2026-68752

cve-icon Vulnrichment

Updated: 2026-08-13T13:21:11.725Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T15:18:21.880

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-68752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management