CVE-2026-69104
Artifactory Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository-level permissions. This can result in partial information disclosure, unauthorized state changes, and service disruption. The vulnerability affects JFrog Artifactory Self-Managed versions 7.161.0 through 7.161.18, and was published on August 25, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).

Detalhes técnicos

The root cause is classified as CWE-862 (Missing Authorization): the repository migration API endpoint fails to verify that the requesting authenticated user holds the necessary repository-level permissions before executing the migration operation. An attacker with any valid Artifactory account can send a network request (low complexity, no user interaction required) to trigger migration operations on repositories they do not own or have read/write access to. No special privileges beyond basic authentication are required, making the attack surface broad in multi-tenant or shared Artifactory deployments (JFrog Advisory, Github Advisory).

Impacto

Successful exploitation allows a low-privileged authenticated user to read sensitive repository data (partial confidentiality impact), alter repository state without authorization (integrity impact), and disrupt service availability — for example, by triggering resource-intensive migration operations that degrade Artifactory performance or cause outages (high availability impact). The vulnerability is scoped to the affected Artifactory instance and does not directly enable lateral movement to other systems, but exposure of repository contents could facilitate further attacks such as supply chain compromise or credential harvesting from stored artifacts (JFrog Advisory, Github Advisory).

Exploração

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (JFrog Advisory). The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not fully automatable. The EPSS score is approximately 0.176%, placing it in the 7th percentile for exploitation likelihood within 30 days. CVE-2026-69104 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory).

Etapas de exploração

  1. Reconnaissance: Identify JFrog Artifactory Self-Managed instances running versions 7.161.0–7.161.18 using network scanning tools or by checking the Artifactory version endpoint (/artifactory/api/system/version).
  2. Authentication: Obtain any valid low-privileged Artifactory user account (e.g., via credential stuffing, phishing, or use of a legitimately provisioned account).
  3. Identify target repositories: Enumerate available repositories using the Artifactory REST API (e.g., GET /artifactory/api/repositories) to identify repositories of interest that the user does not have migration permissions for.
  4. Trigger unauthorized migration: Send a crafted API request to the repository migration endpoint without holding the required repository permissions. Due to the missing authorization check, the server processes the request as if the user were authorized.
  5. Achieve objective: Depending on the migration operation triggered, the attacker may read sensitive artifact data from the target repository, alter its state (e.g., move or restructure content), or cause service disruption by initiating resource-intensive operations (JFrog Advisory, Github Advisory).

Indicadores de compromisso

  • Logs: Artifactory access logs showing repository migration API requests from users who do not hold migration or admin permissions on the targeted repository; unexpected migration-related log entries in artifactory-service.log or access.log associated with low-privileged accounts.
  • Audit Logs: JFrog Artifactory audit logs recording migration operations initiated by non-admin or non-repository-owner users; repeated or bulk migration attempts from a single user account in a short timeframe.
  • Network: Unusual volume of migration-related API calls originating from a single authenticated session or IP address, particularly targeting multiple repositories in rapid succession.
  • Application State: Unexpected changes to repository structure, content, or configuration that do not correspond to authorized administrative actions; repositories appearing in unexpected states post-migration.

Mitigação e soluções alternativas

JFrog has released a patched version for Self-Managed deployments: Artifactory 7.161.19, which addresses CVE-2026-69104 along with several other vulnerabilities. Cloud (SaaS) environments have already been automatically patched and require no action. For self-managed deployments, administrators should upgrade to version 7.161.19 or later immediately. As an interim measure, restrict repository migration operations to only authorized administrators and review audit logs for any unauthorized migration attempts on affected systems (JFrog Advisory, Artifactory Releases).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado Artifactory Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-82329CRITICAL9.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
SimSimAug 28, 2026
CVE-2026-70551HIGH8.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NãoSimAug 25, 2026
CVE-2026-69104HIGH7.6
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NãoSimAug 25, 2026
CVE-2026-70550MEDIUM6.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NãoSimAug 25, 2026
CVE-2026-70548LOW3.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NãoSimAug 25, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades