CVE-2026-69106General(jfrog / artifactory)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jfrog artifactory systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • artifactory

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
artifactory

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-21: 1Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-28: 108-1208-2108-28
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-121
General1
2026-08-211
Disclosure1
2026-08-281
Patch1
Full discourse3 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-69106 (CVSS 8.8) lets unauthenticated users poison JFrog Artifactory shared caches via X-Orig-Client-Uri header abuse; CVE-2026-65922 (CVSS 5.4) lets low-priv users write into trusted .jfrog/ metadata paths. #DFIR_Radar https://t.co/mrwfmUc6Lp

    Post summary

    The tweet announces two JFrog Artifactory vulnerabilities, providing CVE IDs, CVSS scores, and technical details of the exploit vectors, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    10010245
    1.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    JFrog Artifactory の脆弱性 CVE-2026-69106/65922:サプライチェーン攻撃に関する詳細を Oligo が公開 https://iototsecnews.jp/2026/08/20/jfrog-artifactory-flaws-enable-software-supply-chain-attacks/ JFrog Artifactory における脆弱性 CVE-2026-69106/CVE-2026-65922 の動向と対策情報を解説する記事です。この件の背景にあるのは、特定ヘッダーの受け入れや内部メタデータ領域へのアクセス制限不備です。この欠陥により、不正な情報によるキャッシュ汚染/管理データの改ざん/サプライチェーン侵害といった影響が生じる恐れがあります。対応策として、最新修正版へのアップデート/匿名アクセスの無効化/境界ネットワークでの不要ヘッダーの除去/上書きが求められます。 #Artifactory #CVE202665922 #CVE202669106 #JFrog #Vulnerability

    Post summary

    The article outlines the CVE-2026-69106/CVE-2026-65922 vulnerabilities in JFrog Artifactory, explains the technical flaws and potential impacts, and urges users to apply the latest patch and adjust configuration settings.

    00000102
    511 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-69106 Untrusted Content Retrieval via Cached Artifact Metadata Poisonin... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-69106 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post serves simply as a link to a vulnerability listing, with a brief technical description but no further details on exploitation, patching, or PoC.

    00000105
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjfrogartifactory---

Explore more