CVE-2026-68757: Potential improper SAML signature verification in JFrog Artifactory
Published Aug 12, 2026
·Updated
A user with access to a valid SAML response may impersonate another user under specific conditions.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 12, 2026
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-68757?
CVE-2026-68757 has a high severity rating of 7.5.
2
How do I fix CVE-2026-68757?
To fix CVE-2026-68757, ensure that your JFrog Artifactory is updated to the latest version that addresses this vulnerability.
3
What impact does CVE-2026-68757 have on JFrog Artifactory?
CVE-2026-68757 allows a user with access to a valid SAML response to potentially impersonate another user.
4
Is CVE-2026-68757 exploitable remotely?
Yes, CVE-2026-68757 is remotely exploitable as it relies on improper SAML signature verification.
5
What should I do if I am affected by CVE-2026-68757?
If affected by CVE-2026-68757, it is crucial to review your SAML configurations and upgrade to the patched version of JFrog Artifactory.