Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

US Defense Contractors Admit Their CMMC Scores May Not Be Accurate

August 20, 2026

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

August 20, 2026

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

August 20, 2026
Facebook X (Twitter) Instagram
Thursday, August 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»JFrog Artifactory Flaws Enable Software Supply Chain Attacks
Cyber Security

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Team-CWDBy Team-CWDAugust 20, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Two vulnerabilities in JFrog Artifactory have been found which allow anonymous or low-privileged users to manipulate package metadata without modifying the underlying artifacts, creating a potential route to software supply chain compromise.

Oligo Security reported the flaws to JFrog on June 25 and detailed them in research published on August 20. 

The findings cover CVE-2026-69106 (CVSS score 8.8), which affects the handling of the X-Orig-Client-Uri header, and CVE-2026-65922 (CVSS score 5.4), which allows writes into trusted .jfrog/ metadata paths.

Both flaws are listed on the National Vulnerability Database and JFrog has issued fixes. 

Header Trust Enables Shared Cache Poisoning

CVE-2026-69106 stemmed from Artifactory accepting X-Orig-Client-Uri from external clients without verifying that it originated from trusted routing infrastructure.

Oligo found that virtual repositories could turn this into a cross-user cache poisoning issue. In Helm, the full attacker-controlled URL was written into generated metadata while only its 32-bit Java hash was used to determine the cache location.

A different URL could therefore be constructed with the same hash and cause a poisoned index to be served to later users. npm had a separate cache guard, but it checked two other override headers and not X-Orig-Client-Uri.

The researchers also identified a related issue in JFrog’s recommended nginx configuration, where X-Forwarded-Proto could be used to influence generated absolute URLs when a caching reverse proxy was deployed.

Read more on software supply chain attacks: GitHub to Update npm to Thwart Software Supply Chain Attacks

Trusted Metadata Paths Bypass Normal Controls

CVE-2026-65922, on the other hand, affected Artifactory’s handling of internal .jfrog/ metadata. The REST COPY and MOVE APIs and WebDAV MKCOL could reach these paths without the normal protection applied to standard uploads.

The resulting authorization path treated .jfrog/ as trusted, allowing an authenticated user with suitable repository access to place or create content there.

Oligo said these files are consumed by package handlers for functions including npm signing keys, OCI referrers, Docker indexes and Ansible indexes.

The researchers recommended upgrading Artifactory to a patched release and disabling anonymous access where it is not required, particularly in shared or internet-accessible environments.

They also advised reviewing users and service accounts with repository access and stripping or overwriting client-supplied X-Orig-Client-Uri and X-Forwarded-Proto headers at the routing boundary.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNCSC Urges Stronger Controls for Agentic AI Systems
Next Article China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
Team-CWD
  • Website

Related Posts

Cyber Security

How Borussia Dortmund’s IT Chief Makes the Case for Cybersecurity

August 20, 2026
Cyber Security

Exclusive: Linux Foundation’s Akrites to Go Live in September

August 19, 2026
Cyber Security

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw

August 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Mobile app permissions (still) matter more than you may think

February 27, 2026

Why you should never pay to get paid

September 15, 2025

Are AI tutoring tools safe for your kids?

August 10, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.