TWO vulnerabilities in JFrog Artifactory were discovered, allowing low-privileged users to alter package metadata, thus posing a risk for software supply chain attacks. The vulnerabilities, CVE-2026-69106 and CVE-2026-65922, were reported by Oligo Security and are cataloged with CVSS scores of 8.8 and 5.4, respectively. The first issue involves improper validation of the X-Orig-Client-Uri header, leading to potential cache poisoning for different users.
The second vulnerability allows unauthorized writes in trusted .jfrog/ paths, endangering critical metadata for package handling. JFrog has since issued fixes, and users are advised to update their software and review access for security.