
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69104 is a Missing Authorization vulnerability in JFrog Artifactory that allows an authenticated user to initiate repository migration operations without the required repository-level permissions. This can result in partial information disclosure, unauthorized state changes, and service disruption. The vulnerability affects JFrog Artifactory self-managed versions 7.161.0 through 7.161.18, and was published on August 25, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (JFrog Advisory, Github Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the repository migration API endpoint fails to enforce repository-level permission checks before allowing an authenticated user to initiate migration operations. Because the authorization gate is absent, any low-privileged authenticated user can trigger migration workflows that should be restricted to users with explicit repository permissions. The attack is network-accessible, requires no user interaction, and has low attack complexity — the attacker only needs a valid account on the Artifactory instance. No public proof-of-concept or detailed technical write-up has been identified at this time (JFrog Advisory, Github Advisory).
Successful exploitation allows any authenticated user — regardless of their assigned repository permissions — to read sensitive repository data (partial confidentiality impact), alter repository state through unauthorized migration operations (integrity impact), and potentially disrupt service availability by triggering resource-intensive migration jobs (high availability impact). The scope is limited to the affected Artifactory instance, but the ability to trigger migrations on repositories the attacker does not own could expose proprietary artifacts, package metadata, or configuration data stored within those repositories (JFrog Advisory, Github Advisory).
There is no evidence of public proof-of-concept code or active in-the-wild exploitation at this time. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.176% (7th percentile), reflecting a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Github Advisory, JFrog Advisory).
GET /artifactory/api/repositories) to identify repositories of interest that the attacker does not have explicit permissions on.artifactory-service.log or request.log from non-admin users.JFrog has released a patch in Artifactory self-managed version 7.161.19, which addresses CVE-2026-69104. Self-hosted users should upgrade to version 7.161.19 or later immediately. JFrog Cloud environments have already been automatically patched and require no action. As interim mitigations, administrators should restrict repository migration operations to only authorized administrators, review audit logs for unauthorized migration attempts, and consider tightening user permission assignments to limit exposure until the patch is applied (JFrog Advisory, Artifactory Releases).
JFrog disclosed CVE-2026-69104 as part of a broader August 25, 2026 security advisory batch that addressed multiple Artifactory vulnerabilities across severity levels. No notable independent researcher commentary, social media discussion, or significant media coverage specific to this CVE has been identified beyond standard vulnerability database aggregation (JFrog Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."