Find notable cyber news and cases, enriched with sources, timelines, and signals.

JFrog Artifactory metadata manipulation flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

JFrog Artifactory flaws let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues are tracked as CVE-2026-69106 and CVE-2026-65922, and JFrog has issued fixes. One flaw affects X-Orig-Client-Uri handling, while the other allows writes into trusted .jfrog/ metadata paths.

Timeline

  1. 20.08.2026 17:30 2 articles · 1h ago

    Oligo Security reports JFrog Artifactory flaws to JFrog

    Initial Disclosure

    Oligo Security reported CVE-2026-69106 and CVE-2026-65922 to JFrog after finding that JFrog Artifactory let anonymous or low-privileged users manipulate package metadata without changing the underlying artifacts, creating cross-user cache poisoning risk and write access into trusted .jfrog/ metadata paths.

    Show sources