Junglewise Threat Intelligence

CVE-2026-69107: JFrog Artifactory unauthenticated artifact access

CVE-2026-69107 · Severity: medium · CVSS 5.9 · Published 2026-08-12

Technologies: JFrog Artifactory. Vendors: JFrog.

Executive brief

JFrog Artifactory is a widely-used repository manager that stores and controls access to software artifacts like binaries and packages. Under specific conditions, an unauthenticated attacker can bypass access controls and retrieve restricted artifacts, potentially exposing proprietary or sensitive binaries and packages that should remain private.

Technical details

This vulnerability is an authentication bypass or authorization weakness in Artifactory's artifact access control logic. An unauthenticated user can access restricted artifacts under specific conditions—the advisory does not detail the exact preconditions or attack vector, but suggests it may involve cache behavior or specific repository configurations. An attacker can retrieve artifacts they should not have permission to access, compromising confidentiality of stored packages and binaries. Patches are available in Artifactory versions 7.104.16 and later, with fixes in the 7.111, 7.117, 7.125, 7.133, and 7.146 release branches.

Affected products

  • JFrog Artifactory < 7.104.16; 7.111.0–7.111.14; 7.117.0–7.117.21; 7.125.0–7.125.14; 7.133.0–7.133.21; 7.146.0–7.146.8

Timeline

  • 2026-08-12: disclosed

References

Related threats