
PEACH
Un cadre d’isolation des locataires
CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository permissions. The flaw affects JFrog Artifactory Self-Managed versions 7.161.0 through 7.161.18 (i.e., less than 7.161.19). It was published on August 25, 2026, by JFrog as the assigning CNA. The vulnerability carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the repository migration endpoint fails to verify that the requesting authenticated user holds the necessary repository-level permissions before executing the operation. An attacker with any valid Artifactory account can send a network request to trigger migration operations on repositories they do not have access to, requiring no user interaction and low attack complexity. This can result in partial information disclosure (reading sensitive repository data), unauthorized state changes to repository configurations, and service disruption (JFrog Advisory, Github Advisory).
Any authenticated user — regardless of their assigned repository permissions — can initiate repository migration operations, enabling them to read sensitive repository data (partial confidentiality impact), modify repository state (integrity impact), and disrupt service availability (high availability impact). The scope is limited to the affected Artifactory instance, but the availability impact is rated High, meaning a low-privileged insider or compromised account could cause significant disruption to artifact delivery pipelines. There is no evidence of lateral movement beyond the Artifactory platform itself (JFrog Advisory, Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and CISA's SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account on the Artifactory instance, limiting the attack surface to insiders or users with compromised credentials (Github Advisory, JFrog Advisory).
GET /artifactory/api/system/version).GET /artifactory/api/repositories) to identify repositories the attacker does not have migration permissions for.artifactory-service.log or request.log associated with low-privileged users.MIGRATION action types tied to unexpected user identities.JFrog has released a fix in Artifactory Self-Managed version 7.161.19, which addresses CVE-2026-69104. Cloud (SaaS) environments have already been patched automatically and require no action. For self-hosted deployments, administrators should upgrade to version 7.161.19 or later as soon as possible. As an interim measure, restrict repository migration operations to only authorized administrators and review audit logs for any unauthorized migration attempts on affected systems (JFrog Advisory, Artifactory Releases).
JFrog disclosed this vulnerability as part of a broader August 25, 2026 security advisory batch that addressed multiple Artifactory CVEs simultaneously, indicating a coordinated internal security review cycle. No notable independent researcher commentary or significant social media discussion has been identified for this specific CVE at the time of reporting.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."