High severity8.8NVD Advisory· Published Aug 12, 2026· Updated Sep 11, 2026
CVE-2026-69106
CVE-2026-69106
Description
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease Notes
News mentions
3- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- JFrog Artifactory Flaws Enable Software Supply Chain AttacksInfosecurity Magazine · Aug 20, 2026
- JFrog Artifactory: 17 Vulnerabilities Disclosed, Highlighting Access Control and Metadata RisksVypr Intelligence · Aug 12, 2026