CVE-2026-68760
- EPSS 0.37%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 02.09.2026 20:03:45
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68754
- EPSS 0.22%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 02.09.2026 20:05:30
A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68755
- EPSS 0.19%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 02.09.2026 20:05:04
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68756
- EPSS 0.34%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 02.09.2026 20:04:37
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68757
- EPSS 0.19%
- Veröffentlicht 12.08.2026 15:18:22
- Zuletzt bearbeitet 02.09.2026 20:04:15
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68753
- EPSS 0.24%
- Veröffentlicht 12.08.2026 15:18:21
- Zuletzt bearbeitet 02.09.2026 20:05:53
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-68752
- EPSS 0.34%
- Veröffentlicht 12.08.2026 15:18:21
- Zuletzt bearbeitet 02.09.2026 20:06:15
A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-66382
- EPSS 0.26%
- Veröffentlicht 12.08.2026 15:18:20
- Zuletzt bearbeitet 02.09.2026 20:06:41
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381
- EPSS 0.29%
- Veröffentlicht 12.08.2026 15:18:20
- Zuletzt bearbeitet 02.09.2026 20:07:04
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
CVE-2026-66380
- EPSS 0.2%
- Veröffentlicht 12.08.2026 15:18:19
- Zuletzt bearbeitet 02.09.2026 20:07:26
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.