CVE-2026-69106
Awaiting Analysis Awaiting Analysis - Queue

Artifact Metadata Cache Poisoning in JFrog Artifactory

Vulnerability report for CVE-2026-69106, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-28

Assigner: JFrog

Description

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-28
Generated
2026-09-02
AI Q&A
2026-08-13
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jfrog artifactory 7.161.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a low-privileged user to manipulate cached artifact metadata under certain conditions. This could trick systems into retrieving and using untrusted or malicious content instead of legitimate files.

Detection Guidance

To detect this vulnerability, monitor JFrog Artifactory logs for unusual artifact metadata caching behavior. Check for repeated requests to untrusted sources or inconsistencies in cached metadata. Use Artifactory's REST API to audit metadata endpoints and verify integrity of cached artifacts.

Impact Analysis

An attacker could exploit this to distribute malicious software or data to your systems. This may lead to data breaches, system compromise, or unauthorized access if your infrastructure relies on cached artifact metadata.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data access or modification. For GDPR, it may lead to data breaches requiring notification. For HIPAA, it could compromise protected health information integrity.

Mitigation Strategies

Monitor artifact metadata caching processes for unauthorized modifications. Ensure low-privileged users cannot alter cached metadata. Validate artifact sources and integrity before consumption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69106. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart