Description
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
Published: 2026-08-12
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated user to retrieve restricted artifacts when specific conditions are met. This disclosure can lead to confidentiality breaches by exposing proprietary or sensitive binaries, configuration files, or metadata that should only be available to authorized personnel. It represents an access control weakness (CWE-862).

Affected Systems

Version information is not specified in the CNA data, so any instance of JFrog Artifactory that uses the affected code paths could be vulnerable. Administrators should verify whether their deployments rely on the affected components and consult the JFrog documentation for the relevant release notes.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate overall risk. No EPSS score is available, so current exploitation likelihood is unclear. The vulnerability is not yet listed in the CISA KEV catalog, suggesting no confirmed public exploits. The attack vector involves unauthenticated network access under certain conditions, but details are omitted in the description. Due to the lack of a publicly documented exploit, organizations should treat this as a moderate threat pending further information.

Generated by OpenCVE AI on August 12, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Artifactory release that addresses the access control flaw per JFrog advisories.
  • Review and enforce proper authentication and authorization policies, ensuring that artifact repositories are protected by roles and permissions.
  • Monitor access logs for anomalous requests to restricted artifacts and audit artifact visibility settings to confirm that unauthorized access is not possible.

Generated by OpenCVE AI on August 12, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
Title Potential unauthorized artifact access in JFrog Artifactory
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-12T18:15:09.728Z

Reserved: 2026-08-03T10:58:15.519Z

Link: CVE-2026-69107

cve-icon Vulnrichment

Updated: 2026-08-12T18:15:04.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T16:17:20.220

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-69107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:03Z

Weaknesses