Description
A low-privileged authenticated user may access restricted support information under specific conditions.
Published: 2026-08-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged authenticated user may read restricted support information under specific conditions. The likely cause appears to be the absence of an authorization check when serving support data, which allows non‑administrator accounts to access internal diagnostics and configuration details that should be limited to administrators. This information‑disclosure flaw exposes sensitive system information to compromised or low‑privileged users, potentially aiding further attacks.

Affected Systems

JFrog Artifactory is affected. No specific release numbers are cited in the advisory, so any installation of Artifactory that has not yet applied the vendor’s fix may be vulnerable. All users with low‑privileged authenticated access should be considered at risk until the remediation is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable only after authentication, meaning an attacker must first gain legitimate credentials or otherwise authenticate to a low‑privileged account. Once authenticated, an attacker can target the support endpoint to retrieve privileged information, but there is no evidence of remote code execution or privilege escalation from the available data.

Generated by OpenCVE AI on August 13, 2026 at 00:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Artifactory release that incorporates the vendor’s fix.
  • Restrict access to the support endpoints for low‑privileged users by configuring the application or reverse proxy to block these routes until the patch is applied.
  • Review and tighten user role permissions so that only administrators retain the capability to view support information.

Generated by OpenCVE AI on August 13, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A low-privileged authenticated user may access restricted support information under specific conditions.
Title Authenticated users may access restricted Artifactory support information
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-12T18:42:43.960Z

Reserved: 2026-07-31T13:38:38.864Z

Link: CVE-2026-68758

cve-icon Vulnrichment

Updated: 2026-08-12T18:42:37.176Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T16:17:15.540

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-68758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:00:10Z

Weaknesses