CVE-2026-69106: JFrog Artifactory

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

Affected products

  • JFrog Artifactory: before 7.146.28 (fixed in 7.146.28)

Published 2026-08-12. Last modified 2026-09-11.