CVE-2026-69104: Potential unauthorized repository migration in JFrog Artifactory
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated and have low-level privileges. No user interaction is required, and the attack can be performed remotely over the network.
What could a successful exploit allow?
A successful exploit may let the attacker initiate repository migration operations without the required repository permissions. This could disclose information, make unauthorized repository state changes, or disrupt service availability.
How should teams remediate this vulnerability?
Upgrade JFrog Artifactory to a fixed version identified in the vendor's security advisory or self-managed release documentation. The provided information does not identify the affected or fixed version numbers.