CVE-2026-69106
- EPSS 0.35%
- Veröffentlicht 12.08.2026 17:48:29
- Zuletzt bearbeitet 13.08.2026 15:19:58
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-42018
- EPSS 0.3%
- Veröffentlicht 12.08.2026 17:43:21
- Zuletzt bearbeitet 18.08.2026 19:16:48
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-69107
- EPSS 0.28%
- Veröffentlicht 12.08.2026 15:51:47
- Zuletzt bearbeitet 12.08.2026 19:17:54
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-69105
- EPSS 0.13%
- Veröffentlicht 12.08.2026 15:19:40
- Zuletzt bearbeitet 13.08.2026 16:18:55
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-70547
- EPSS 0.2%
- Veröffentlicht 12.08.2026 15:18:29
- Zuletzt bearbeitet 13.08.2026 16:19:02
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-68754
- EPSS 0.22%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 12.08.2026 17:17:30
A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68755
- EPSS 0.19%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 12.08.2026 17:17:30
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68760
- EPSS 0.37%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 12.08.2026 19:17:54
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68757
- EPSS 0.19%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 12.08.2026 20:17:48
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68756
- EPSS 0.34%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 13.08.2026 05:17:25
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.