Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3879 articles · 205847 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-69106PATCHED
jfrog · artifactory

Potential cache poisoning in JFrog Artifactory

Description

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

Affected Products

VendorProductVersions
jfrogartifactory0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jfrogartifactorycert_advisory90%

References

  • https://docs.jfrog.com/releases/docs/jfrog-security-advisories(vendor-advisory)
  • https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases(vendor-advisory)

Related News (3 articles)

Tier D
Infosecurity Magazine9d ago
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
→ No new info (linked only)
Tier B
BSI Advisories16d ago
[NEU] [hoch] JFrog Artifactory: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB16d ago
CVE-2026-69106 | JFrog Artifactory up to 7.146.28 input validation
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.146.29
CWECWE-20
PublishedAug 12, 2026
Trending Score16
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-66384EXPKEV
Authenticated users may write data outside the intended Docker cache path
Trending: 106
HIGHCVE-2026-70551
Server-Side Request Forgery Via VCS remote download in JFrog Artifactory
Trending: 25
HIGHCVE-2026-69104
Potential unauthorized repository migration in JFrog Artifactory
Trending: 25
MEDIUMCVE-2026-70550
Potential unauthorized access to private Composer repository metadata in JFrog Artifactory
Trending: 22
LOWCVE-2026-70548
SSRF In CocoaPods Via JFrog Artifactory External Dependency
Trending: 21

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 13, 2026