CVE-2026-69104
Artifactory Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository permissions. The flaw affects JFrog Artifactory Self-Managed versions 7.161.0 through 7.161.18 (i.e., less than 7.161.19). It was published on August 25, 2026, by JFrog as the assigning CNA. The vulnerability carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).

Détails techniques

The root cause is classified as CWE-862 (Missing Authorization): the repository migration endpoint fails to verify that the requesting authenticated user holds the necessary repository-level permissions before executing the operation. An attacker with any valid Artifactory account can send a network request to trigger migration operations on repositories they do not have access to, requiring no user interaction and low attack complexity. This can result in partial information disclosure (reading sensitive repository data), unauthorized state changes to repository configurations, and service disruption (JFrog Advisory, Github Advisory).

Impact

Any authenticated user — regardless of their assigned repository permissions — can initiate repository migration operations, enabling them to read sensitive repository data (partial confidentiality impact), modify repository state (integrity impact), and disrupt service availability (high availability impact). The scope is limited to the affected Artifactory instance, but the availability impact is rated High, meaning a low-privileged insider or compromised account could cause significant disruption to artifact delivery pipelines. There is no evidence of lateral movement beyond the Artifactory platform itself (JFrog Advisory, Github Advisory).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and CISA's SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account on the Artifactory instance, limiting the attack surface to insiders or users with compromised credentials (Github Advisory, JFrog Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify a JFrog Artifactory Self-Managed instance running a version between 7.161.0 and 7.161.18. Confirm the version via the Artifactory UI or API (e.g., GET /artifactory/api/system/version).
  2. Authentication: Obtain any valid low-privileged user account on the target Artifactory instance (e.g., a developer or read-only account).
  3. Identify target repositories: Enumerate available repositories using the Artifactory REST API (e.g., GET /artifactory/api/repositories) to identify repositories the attacker does not have migration permissions for.
  4. Trigger unauthorized migration: Send a crafted API request to the repository migration endpoint without holding the required repository permissions. Due to the missing authorization check, the server processes the request.
  5. Achieve impact: Depending on the migration operation triggered, the attacker may read partial repository data (information disclosure), alter repository state (unauthorized state change), or cause service disruption affecting artifact availability (JFrog Advisory).

Indicateurs de compromis

  • Logs: Artifactory access logs showing repository migration API calls from user accounts that do not hold migration or admin permissions on the targeted repositories; unexpected migration-related log entries in artifactory-service.log or request.log associated with low-privileged users.
  • Audit Logs: JFrog Platform audit logs recording migration operation events initiated by non-administrative users or users without repository-level permissions — review for anomalous MIGRATION action types tied to unexpected user identities.
  • Network: Unusual API calls to repository migration endpoints originating from internal low-privileged service accounts or developer accounts outside of normal maintenance windows.

Atténuation et solutions de contournement

JFrog has released a fix in Artifactory Self-Managed version 7.161.19, which addresses CVE-2026-69104. Cloud (SaaS) environments have already been patched automatically and require no action. For self-hosted deployments, administrators should upgrade to version 7.161.19 or later as soon as possible. As an interim measure, restrict repository migration operations to only authorized administrators and review audit logs for any unauthorized migration attempts on affected systems (JFrog Advisory, Artifactory Releases).

Réactions de la communauté

JFrog disclosed this vulnerability as part of a broader August 25, 2026 security advisory batch that addressed multiple Artifactory CVEs simultaneously, indicating a coordinated internal security review cycle. No notable independent researcher commentary or significant social media discussion has been identified for this specific CVE at the time of reporting.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Artifactory Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82329CRITICAL9.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NonOuiAug 28, 2026
CVE-2026-70551HIGH8.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NonOuiAug 25, 2026
CVE-2026-69104HIGH7.6
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NonOuiAug 25, 2026
CVE-2026-70550MEDIUM6.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NonOuiAug 25, 2026
CVE-2026-70548LOW3.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NonOuiAug 25, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités