Stored Session Data Vulnerability in JFrog Artifactory by JFrog
CVE-2026-68756

6.6MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68756?

A vulnerability exists in JFrog Artifactory where users with write access to stored session data could potentially manipulate this data under certain conditions. This could lead to unauthorized actions or data exposure, emphasizing the importance of proper access controls and data integrity mechanisms.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Morris in collaboration with Claude and Anthropic Research
.