JFrog Artifactory < 7.146.35 Multiple Vulnerabilities

high Nessus Plugin ID 347964

Synopsis

An application installed on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the version of JFrog Artifactory installed on the remote host is prior to 7.146.35. It is, therefore, affected by the following vulnerabilities.

- An authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. (CVE-2026-65926)

- Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. (CVE-2026-66016)

- A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. (CVE-2026-66375)

- Credentials for a deleted user may remain valid for a short period under specific conditions.
(CVE-2026-66376)

- An unauthenticated user may access restricted repository information under specific conditions.
(CVE-2026-66377)

- An authenticated user without repository read permission may access private NuGet metadata under specific conditions. (CVE-2026-66378)

- An authenticated user may view private Puppet module metadata without repository read access.
(CVE-2026-66379)

- An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions. (CVE-2026-66380)

- A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. (CVE-2026-66381)

- An authenticated user may write files outside the intended Artifactory work directory under specific conditions. (CVE-2026-66382)

- An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. (CVE-2026-66384)

- A Project Resource Manager may gain broader administrative privileges under specific conditions.
(CVE-2026-68752)

- An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way. (CVE-2026-68753)

- A repository publisher without delete permission may modify protected package content under specific conditions. (CVE-2026-68754)

- A bundle writer may create misleading release promotion information under specific conditions.
(CVE-2026-68755)

- A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
(CVE-2026-68756)

- A user with access to a valid SAML response may impersonate another user under specific conditions.
(CVE-2026-68757)

- A low-privileged authenticated user may access restricted support information under specific conditions.
(CVE-2026-68758)

- A holder of a valid integration credential may impersonate other users under specific conditions.
(CVE-2026-68759)

- An unauthenticated user may bypass authentication under specific cache conditions. (CVE-2026-68760)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to JFrog Artifactory version 7.146.35, or later.

See Also

https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases

https://docs.jfrog.com/releases/docs/jfrog-security-advisories

Plugin Details

Severity: High

ID: 347964

File Name: jfrog_artifactory_7_146_35.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 9/18/2026

Updated: 9/18/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.14

CVSS v2

Risk Factor: High

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2026-66375

CVSS v3

Risk Factor: High

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Vulnerability Information

CPE: cpe:/a:jfrog:artifactory

Required KB Items: installed_sw/Artifactory

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 8/12/2026

CISA Known Exploited Vulnerability Due Dates: 9/10/2026

Reference Information

CVE: CVE-2026-65926, CVE-2026-66016, CVE-2026-66375, CVE-2026-66376, CVE-2026-66377, CVE-2026-66378, CVE-2026-66379, CVE-2026-66380, CVE-2026-66381, CVE-2026-66382, CVE-2026-66384, CVE-2026-68752, CVE-2026-68753, CVE-2026-68754, CVE-2026-68755, CVE-2026-68756, CVE-2026-68757, CVE-2026-68758, CVE-2026-68759, CVE-2026-68760

IAVA: 2026-A-0915