CVE-2026-69107Disclosure(jfrog / artifactory)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jfrog artifactory systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • artifactory

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
artifactory

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • DFIR Radar@DFIR_Radar
    Disclosure

    Two chained CVEs in JFrog Artifactory let an unauthenticated attacker bypass auth, traverse paths, and exfiltrate arbitrary artifacts. All OSS and Enterprise versions below the patched releases were affected. Key findings: - CVE-2026-42018 (auth bypass): POSTing to /access/api/v1/aws/token/ with a trailing slash causes AntPathMatcher to skip AwsTokenAuthenticationFilter entirely. Spring's fallback AnonymousAuthenticationFilter then populates the security context, and the AWS token endpoint mints a valid JWT for the anonymous user, even when anonymous access is disabled. Patch: Artifactory 7.146.8. - CVE-2026-69107 (missing authz + path traversal): The JWT unlocks the deprecated stash API. An attacker POSTs arbitrary repoKey and relativePath values; FileInfo (sha1, sha256, size) is loaded into the session with no ACL check. The stash export then concatenates an attacker-controlled name containing ../ sequences with a base directory, and forceMkdir resolves the traversal, dropping the artifact into the Tomcat web root. - Bug 4 completes the production chain: jf-router does not normalize paths before proxying, so /artifactory/..;/markertag-20260713.141536/sample-v1.0.0 routes through Traefik to Tomcat, which strips the path parameter and serves the file unauthenticated. - The stash oracle is a bonus primitive: a 200 vs error response confirms whether a repo name and artifact path exist, enabling blind enumeration before full exfiltration. #DFIR_Radar

    Post summary

    The message discloses two chained CVEs in JFrog Artifactory that enable unauthenticated authentication bypass, path traversal, and artifact exfiltration, and it specifies a patch version for remediation.

    10000228
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjfrogartifactory---

Explore more