Description
A user with access to a valid SAML response may impersonate another user under specific conditions.
Published: 2026-08-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user who can obtain a valid SAML response can, under specific conditions, authenticate as a different Artifactory user. This flaw arises from improper verification of the SAML signature, allowing the attacker to forge or replay assertions that reference another account. The resulting privilege escalation enables the attacker to access artifacts, modify configurations, or carry out other privileged actions without authorization.

Affected Systems

The vulnerability affects JFrog Artifactory installations that rely on SAML for authentication. No specific product version is listed, so any deployment of Artifactory that accepts SAML assertions is potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity flaw. EPSS data is unavailable, and the vulnerability is not currently catalogued in the CISA KEV list. The likely attack vector is an attacker in possession of a valid SAML response, perhaps through social engineering or an existing compromised identity provider, who can then impersonate another user. The exploit requires no additional privileges beyond those that allow the attacker to acquire the response, making the vulnerability particularly dangerous in multi-tenant or shared environments.

Generated by OpenCVE AI on August 12, 2026 at 23:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JFrog Artifactory to the latest version that includes the SAML signature verification fix
  • Reconfigure Artifactory to enforce signature validation on all SAML assertions and disable any legacy options that allow unsigned or unverified assertions
  • Validate that your identity provider signs all SAML assertions and that Artifactory rejects any unsigned or improperly signed responses

Generated by OpenCVE AI on August 12, 2026 at 23:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A user with access to a valid SAML response may impersonate another user under specific conditions.
Title Potential improper SAML signature verification in JFrog Artifactory
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-12T19:01:38.242Z

Reserved: 2026-07-31T13:38:38.864Z

Link: CVE-2026-68757

cve-icon Vulnrichment

Updated: 2026-08-12T19:01:33.904Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T15:18:22.477

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-68757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature