JFrog artifactory是美国JFrog公司的一个二进制制品仓库管理平台。 JFrog artifactory 7.146.35之前版本和7.161.0至7.161.16之前版本存在加密问题漏洞,该漏洞源于特定自托管Helm配置下生成的TLS私钥可能保留在渲染的manifest中,可被高权限本地用户访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jfrog | artifactory | < 7.146.35 |
affected |
7.161.0< 7.161.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jfrog | artifactory | 0 ~ 7.146.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69106 | 8.8 HIGH | Potential cache poisoning in JFrog Artifactory |
| CVE-2026-69105 | 8.1 HIGH | Potential package cache integrity issue in JFrog Artifactory |
| CVE-2026-66375 | 8.1 HIGH | Low-privilege users may remove protected Artifactory metadata |
| CVE-2026-42018 | 7.5 HIGH | Anonymous user token generation exposure in JFrog Artifactory |
| CVE-2026-68757 | 7.5 HIGH | Potential improper SAML signature verification in JFrog Artifactory |
| CVE-2026-68759 | 7.2 HIGH | Integration credential holders may impersonate users in JFrog Access |
| CVE-2026-68752 | 7.2 HIGH | Project Resource Managers may escalate privileges in JFrog Artifactory |
| CVE-2026-68756 | 6.6 MEDIUM | Potential insecure deserialization in JFrog Artifactory |
| CVE-2026-68754 | 6.5 MEDIUM | Publishers without delete permission can overwrite docker layer information |
| CVE-2026-68758 | 6.5 MEDIUM | Authenticated users may access restricted Artifactory support information |
| CVE-2026-69107 | 5.9 MEDIUM | Potential unauthorized artifact access in JFrog Artifactory |
| CVE-2026-68760 | 5.3 MEDIUM | Potential remember-me authentication bypass in JFrog Artifactory |
| CVE-2026-68753 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory content under specific configurations |
| CVE-2026-66377 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory repository information |
| CVE-2026-66384 | 5.3 MEDIUM | Authenticated users may write data outside the intended Docker cache path |
| CVE-2026-66381 | 5.3 MEDIUM | Repository readers may access content outside configured upstream paths |
| CVE-2026-68755 | 4.3 MEDIUM | Bundle writers may alter trusted release information in JFrog Artifactory |
| CVE-2026-66382 | 4.3 MEDIUM | Authenticated users may write files outside the intended Artifactory work directory |
| CVE-2026-66380 | 4.3 MEDIUM | Authenticated users may access private OCI referrer metadata |
| CVE-2026-66378 | 4.3 MEDIUM | Authenticated users may access private NuGet metadata |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet