
PEACH
Un framework di isolamento del tenant
CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository-level permissions. This can result in partial information disclosure, unauthorized state changes, and service disruption. The vulnerability affects JFrog Artifactory Self-Managed versions 7.161.0 through 7.161.18, and was published on August 25, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the repository migration API endpoint fails to verify that the requesting authenticated user holds the necessary repository-level permissions before executing the migration operation. An attacker with any valid Artifactory account can send a network request (low complexity, no user interaction required) to trigger migration operations on repositories they do not own or have read/write access to. No special privileges beyond basic authentication are required, making the attack surface broad in multi-tenant or shared Artifactory deployments (JFrog Advisory, Github Advisory).
Successful exploitation allows a low-privileged authenticated user to read sensitive repository data (partial confidentiality impact), alter repository state without authorization (integrity impact), and disrupt service availability — for example, by triggering resource-intensive migration operations that degrade Artifactory performance or cause outages (high availability impact). The vulnerability is scoped to the affected Artifactory instance and does not directly enable lateral movement to other systems, but exposure of repository contents could facilitate further attacks such as supply chain compromise or credential harvesting from stored artifacts (JFrog Advisory, Github Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (JFrog Advisory). The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not fully automatable. The EPSS score is approximately 0.176%, placing it in the 7th percentile for exploitation likelihood within 30 days. CVE-2026-69104 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory).
/artifactory/api/system/version).GET /artifactory/api/repositories) to identify repositories of interest that the user does not have migration permissions for.artifactory-service.log or access.log associated with low-privileged accounts.JFrog has released a patched version for Self-Managed deployments: Artifactory 7.161.19, which addresses CVE-2026-69104 along with several other vulnerabilities. Cloud (SaaS) environments have already been automatically patched and require no action. For self-managed deployments, administrators should upgrade to version 7.161.19 or later immediately. As an interim measure, restrict repository migration operations to only authorized administrators and review audit logs for any unauthorized migration attempts on affected systems (JFrog Advisory, Artifactory Releases).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."