JFrog Artifactory metadata manipulation flaws (multiple vulnerabilities)
VulnerabilityFirst reported
Last updated
Happening score
H score
25
Summary
Hide ▲
Show ▼
JFrog Artifactory flaws let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues are tracked as CVE-2026-69106 and CVE-2026-65922, and JFrog has issued fixes. One flaw affects X-Orig-Client-Uri handling, while the other allows writes into trusted .jfrog/ metadata paths.
Timeline
-
20.08.2026 17:30 2 articles · 1h ago
Oligo Security reports JFrog Artifactory flaws to JFrog
Initial DisclosureOligo Security reported CVE-2026-69106 and CVE-2026-65922 to JFrog after finding that JFrog Artifactory let anonymous or low-privileged users manipulate package metadata without changing the underlying artifacts, creating cross-user cache poisoning risk and write access into trusted .jfrog/ metadata paths.
Show sources
- JFrog Artifactory Flaws Enable Software Supply Chain Attacks — www.infosecurity-magazine.com — 20.08.2026 17:30
- JFrog Artifactory Flaws Enable Software Supply Chain Attacks — www.infosecurity-magazine.com — 20.08.2026 17:30