JFrog Artifactory flaws risk supply chain metadata poisoning
🔒 Two vulnerabilities in JFrog Artifactory let anonymous or low-privileged users manipulate package metadata without altering artifacts, creating a potential software supply chain risk. Oligo Security reported the flaws to JFrog on June 25 and published research on August 20 detailing CVE-2026-69106 (score 8.8) and CVE-2026-65922 (score 5.4). The issues concern unverified X-Orig-Client-Uri header handling and writes into trusted .jfrog/ metadata paths. JFrog has issued fixes; operators are advised to upgrade, restrict anonymous access, and strip or overwrite hazardous headers at the routing boundary.
