Privilege Escalation in Project Resource Manager by JFrog
CVE-2026-68752

7.2HIGH

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68752?

A vulnerability exists in JFrog's Project Resource Manager that allows a user with limited privileges to escalate their access to obtain broader administrative permissions. This exploitation could occur under specific conditions, potentially allowing unauthorized actions within the Project Resource Manager environment.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OpenAI
.