Junglewise Threat Intelligence

CVE-2026-69104: JFrog Artifactory privilege escalation in repository migration

CVE-2026-69104 · Severity: high · CVSS 7.6 · Published 2026-08-25

Technologies: JFrog Artifactory. Vendors: JFrog.

Executive brief

JFrog Artifactory is a widely-used artifact repository platform that manages software packages and binaries for organizations. An authenticated user can initiate repository migration operations without the required permissions, allowing unauthorized state changes, data exposure, and service disruption. This could enable attackers to move, copy, or exfiltrate sensitive software artifacts that should be restricted from their access.

Technical details

The vulnerability is an authorization bypass in Artifactory's repository migration functionality. An authenticated user, even without explicit repository permissions, can trigger migration operations that should require elevated privileges. This is a broken access control issue on a privileged operation. Attack vector is network-based and requires authentication, but no additional user interaction is needed once authenticated. An attacker can exploit this to migrate repositories, potentially causing unauthorized state changes, information disclosure of restricted artifacts, and service disruption. Patches are available in Artifactory 7.161.18 and later.

Affected products

  • JFrog Artifactory 7.161.0 through 7.161.18

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in version 7.161.18 and later

References

Related threats