Description
A bundle writer may create misleading release promotion information under specific conditions.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A bundle writer can create misleading release promotion information when certain conditions are met, potentially causing the system to record or display incorrect release data. This flaw lets an attacker corrupt the integrity of release records, which may lead to failed deployments, audit failures, or other operational issues. The weakness is a permission management error, as identified by CWE‑863.

Affected Systems

The vulnerability affects the JFrog Artifactory product from JFrog. No specific version information is available in the CNA or the advisory, so all installations of Artifactory that allow bundle writing should be considered potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk profile. Because the EPSS score is not available, the likelihood of exploitation is uncertain, but the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the ability to act as a bundle writer, implying that a malicious actor would need some privileged access or would exploit a way to inject a bundle. Under those conditions, the vulnerability could be used to inject false promotion data. The exploit is not trivially available and would require a pre‑existing activity or compromise to reach the bundle writer role.

Generated by OpenCVE AI on August 12, 2026 at 23:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit bundle writer permissions to a narrow subset of users, ensuring only trusted personnel can create bundles.
  • Enforce role‑based access controls and verify that bundle writer roles do not have privileges to alter release promotion settings.
  • Enable audit logging for release promotion changes and regularly review logs for anomalous activity.

Generated by OpenCVE AI on August 12, 2026 at 23:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A bundle writer may create misleading release promotion information under specific conditions.
Title Bundle writers may alter trusted release information in JFrog Artifactory
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-12T16:11:43.313Z

Reserved: 2026-07-31T13:38:38.864Z

Link: CVE-2026-68755

cve-icon Vulnrichment

Updated: 2026-08-12T16:11:39.326Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T15:18:22.237

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-68755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses