CVE-2026-68755: Bundle writers may alter trusted release information in JFrog Artifactory
Published Aug 12, 2026
·Updated
A bundle writer may create misleading release promotion information under specific conditions.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 12, 2026
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-68755?
CVE-2026-68755 has a medium severity score of 4.3.
2
How do I fix CVE-2026-68755?
To mitigate CVE-2026-68755, ensure proper user permissions for bundle writers in JFrog Artifactory.
3
What does CVE-2026-68755 impact?
CVE-2026-68755 affects JFrog Artifactory and allows bundle writers to alter trusted release information.
4
What could a bundle writer do under CVE-2026-68755?
A bundle writer could create misleading release promotion information under certain conditions in JFrog Artifactory.
5
When was CVE-2026-68755 published?
CVE-2026-68755 was published on August 12, 2026.