CVE-2026-68757: Potential improper SAML signature verification in JFrog Artifactory
Published Aug 12, 2026
·Updated
A user with access to a valid SAML response may impersonate another user under specific conditions.
Affected Software
3 affected components
JFrog Artifactory
JFrog Artifactory<7.146.35
JFrog Artifactory>=7.161.0<7.161.16
Event History
Aug 12, 2026
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-68757?
CVE-2026-68757 has a high severity rating of 7.5.
2
How do I fix CVE-2026-68757?
To fix CVE-2026-68757, ensure that your JFrog Artifactory is updated to the latest version that addresses this vulnerability.
3
What impact does CVE-2026-68757 have on JFrog Artifactory?
CVE-2026-68757 allows a user with access to a valid SAML response to potentially impersonate another user.
4
Is CVE-2026-68757 exploitable remotely?
Yes, CVE-2026-68757 is remotely exploitable as it relies on improper SAML signature verification.
5
What should I do if I am affected by CVE-2026-68757?
If affected by CVE-2026-68757, it is crucial to review your SAML configurations and upgrade to the patched version of JFrog Artifactory.