Junglewise Threat Intelligence

CVE-2026-68758: JFrog Artifactory information disclosure in support data

CVE-2026-68758 · Severity: medium · CVSS 6.5 · Published 2026-08-12

Technologies: JFrog Artifactory. Vendors: JFrog.

Executive brief

JFrog Artifactory is a widely-used artifact repository manager that stores and manages software packages and builds. A low-privileged authenticated user can access restricted support information through a specific exploitation path, potentially exposing internal system details, logs, or diagnostic data not intended for that user's access level.

Technical details

This is an authorization bypass vulnerability affecting JFrog Artifactory. A low-privileged authenticated user can circumvent access controls under specific conditions to retrieve support-related information that should be restricted to administrators or support personnel. The vulnerability is network-reachable and requires valid authentication credentials, but does not require elevated privileges. The attack allows information disclosure; no code execution or data modification is possible via this path. Patches have been released in affected version streams.

Affected products

  • JFrog Artifactory <7.146.35; 7.161.0 → 7.161.16

Timeline

  • 2026-08-12: disclosed

References

Related threats