All findings

CVE-2026-66376 + 3 more high

JFrog Artifactory directly credits Claude across four authentication flaws

JFrog's CNA records credit Ben Morris in collaboration with Claude and Anthropic Research on four Artifactory vulnerabilities.

Bug class
Stale credentials, insecure deserialization, SAML verification, and remember-me authentication flaws
Affected codebase
JFrog Artifactory
Credited system
Claude / Anthropic Research
Disclosed
August 12, 2026
Attribution
Direct source attribution
Severity
high
Source status: JFrog's CNA records directly credit Ben Morris in collaboration with Claude and Anthropic Research. JFrog publishes fixes and scores ranging from medium to high; the cluster uses the highest upstream severity.

Summary

The four records cover a short-lived credential-validity window after user deletion, a deserialization path involving writable session data, SAML signature-verification behavior, and a remember-me cache authentication bypass.

This is direct affected-vendor attribution, not an inference from JFrog’s separate commercial integration with Claude Code.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.