CVE-2026-69106High· 8.8▾ TwilightA low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
artifactory < 7.146.28Upgrade past the affected range:
artifactory 7.146.28Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42016High· 8.1Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
CVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory
CVE-2026-66014High· 8.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-69107Medium· 5.9An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-70547Medium· 4.3An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69105High· 8.1An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.