JFrog artifactory是美国JFrog公司的一个二进制制品仓库管理平台。 JFrog artifactory 7.146.35之前版本和7.161.0至7.161.16之前版本存在路径遍历漏洞,该漏洞源于路径处理不当,可能导致经过身份验证的用户在特定条件下将文件写入预期工作目录之外。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jfrog | artifactory | < 7.146.35 |
affected |
7.161.0< 7.161.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jfrog | artifactory | 0 ~ 7.146.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69106 | 8.8 HIGH | Potential cache poisoning in JFrog Artifactory |
| CVE-2026-66375 | 8.1 HIGH | Low-privilege users may remove protected Artifactory metadata |
| CVE-2026-69105 | 8.1 HIGH | Potential package cache integrity issue in JFrog Artifactory |
| CVE-2026-68757 | 7.5 HIGH | Potential improper SAML signature verification in JFrog Artifactory |
| CVE-2026-42018 | 7.5 HIGH | Anonymous user token generation exposure in JFrog Artifactory |
| CVE-2026-68759 | 7.2 HIGH | Integration credential holders may impersonate users in JFrog Access |
| CVE-2026-68752 | 7.2 HIGH | Project Resource Managers may escalate privileges in JFrog Artifactory |
| CVE-2026-66016 | 6.7 MEDIUM | Rendered Artifactory Helm manifests may contain generated TLS private keys |
| CVE-2026-68756 | 6.6 MEDIUM | Potential insecure deserialization in JFrog Artifactory |
| CVE-2026-68754 | 6.5 MEDIUM | Publishers without delete permission can overwrite docker layer information |
| CVE-2026-68758 | 6.5 MEDIUM | Authenticated users may access restricted Artifactory support information |
| CVE-2026-69107 | 5.9 MEDIUM | Potential unauthorized artifact access in JFrog Artifactory |
| CVE-2026-66377 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory repository information |
| CVE-2026-66384 | 5.3 MEDIUM | Authenticated users may write data outside the intended Docker cache path |
| CVE-2026-66381 | 5.3 MEDIUM | Repository readers may access content outside configured upstream paths |
| CVE-2026-68753 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory content under specific configurations |
| CVE-2026-68760 | 5.3 MEDIUM | Potential remember-me authentication bypass in JFrog Artifactory |
| CVE-2026-68755 | 4.3 MEDIUM | Bundle writers may alter trusted release information in JFrog Artifactory |
| CVE-2026-70547 | 4.3 MEDIUM | Potential unauthorized metadata exposure in JFrog Artifactory |
| CVE-2026-66380 | 4.3 MEDIUM | Authenticated users may access private OCI referrer metadata |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet