CVE-2026-69104
Artifactory vulnerability analysis and mitigation

Overview

CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository-level permissions. This can result in partial information disclosure, unauthorized state changes, and service disruption. The vulnerability affects JFrog Artifactory self-managed versions 7.161.0 through 7.161.18, and was published on August 25, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the repository migration API endpoint fails to enforce repository-level permission checks before allowing an authenticated user to initiate migration operations. Because the authorization gate is absent, any low-privileged authenticated user can trigger migration workflows that should be restricted to users with explicit repository permissions. The attack is network-accessible, requires no user interaction, and has low attack complexity — the attacker only needs a valid account on the Artifactory instance. No public proof-of-concept or detailed technical write-up has been identified at this time (JFrog Advisory, Github Advisory).

Impact

Successful exploitation allows any authenticated user — regardless of their assigned repository permissions — to read sensitive repository data (partial confidentiality impact), alter repository state through unauthorized migration operations (integrity impact), and potentially disrupt service availability by triggering resource-intensive migration jobs (high availability impact). The scope is limited to the affected Artifactory instance, but the ability to trigger migrations on repositories the attacker does not own could expose proprietary artifacts, package metadata, or configuration data stored within those repositories (JFrog Advisory, Github Advisory).

Exploitability

There is no evidence of public proof-of-concept code or active in-the-wild exploitation at this time. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.176% (7th percentile), reflecting a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Github Advisory, JFrog Advisory).

Exploitation steps

  1. Reconnaissance: Identify JFrog Artifactory self-managed instances running versions 7.161.0–7.161.18 using network scanning or Shodan/Censys queries targeting Artifactory's default ports and version disclosure endpoints.
  2. Authentication: Obtain any valid low-privileged user account on the target Artifactory instance (e.g., via credential stuffing, phishing, or use of a legitimately provisioned account).
  3. Identify target repositories: Enumerate available repositories using Artifactory's REST API (e.g., GET /artifactory/api/repositories) to identify repositories of interest that the attacker does not have explicit permissions on.
  4. Trigger unauthorized migration: Send a crafted API request to the repository migration endpoint without the required repository permissions. Due to the missing authorization check (CWE-862), the server processes the request and initiates the migration operation.
  5. Achieve objective: Depending on the migration operation's behavior, the attacker may read sensitive artifact or metadata content from the migrated repository, alter its state, or cause service disruption by initiating resource-intensive migration jobs on multiple repositories (JFrog Advisory, Github Advisory).

Indicators of compromise

  • Logs: Artifactory access logs showing repository migration API requests initiated by low-privileged user accounts that do not hold repository-level permissions on the targeted repositories; unexpected migration-related log entries in artifactory-service.log or request.log from non-admin users.
  • Audit Logs: JFrog Platform audit logs recording migration operations triggered by users without appropriate repository permissions; repeated or bulk migration requests from a single user account in a short time window.
  • Network: Unusual volume of API calls to Artifactory migration endpoints from authenticated but low-privileged accounts, particularly outside normal business hours.
  • Application Behavior: Unexpected repository state changes, missing or altered artifacts, or degraded Artifactory performance consistent with resource-intensive migration jobs being triggered without administrative initiation (JFrog Advisory).

Mitigation and workarounds

JFrog has released a patch in Artifactory self-managed version 7.161.19, which addresses CVE-2026-69104. Self-hosted users should upgrade to version 7.161.19 or later immediately. JFrog Cloud environments have already been automatically patched and require no action. As interim mitigations, administrators should restrict repository migration operations to only authorized administrators, review audit logs for unauthorized migration attempts, and consider tightening user permission assignments to limit exposure until the patch is applied (JFrog Advisory, Artifactory Releases).

Community reactions

JFrog disclosed CVE-2026-69104 as part of a broader August 25, 2026 security advisory batch that addressed multiple Artifactory vulnerabilities across severity levels. No notable independent researcher commentary, social media discussion, or significant media coverage specific to this CVE has been identified beyond standard vulnerability database aggregation (JFrog Advisory).

Additional resources


SourceThis report was generated using AI

Related Artifactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82329CRITICAL9.8
  • Artifactory logoArtifactory
  • artifactory
YesYesAug 28, 2026
CVE-2026-70551HIGH8.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 25, 2026
CVE-2026-69104HIGH7.6
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 25, 2026
CVE-2026-70550MEDIUM6.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 25, 2026
CVE-2026-70548LOW3.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management