Source status: JFrog's CNA records directly credit Ben Morris in collaboration with Claude and Anthropic Research. JFrog publishes fixes and scores ranging from medium to high; the cluster uses the highest upstream severity.
Summary
The four records cover a short-lived credential-validity window after user deletion, a deserialization path involving writable session data, SAML signature-verification behavior, and a remember-me cache authentication bypass.
This is direct affected-vendor attribution, not an inference from JFrog’s separate commercial integration with Claude Code.
References
- JFrog security advisories
- CVE record: CVE-2026-66376
- CVE record: CVE-2026-68756
- CVE record: CVE-2026-68757
- CVE record: CVE-2026-68760
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.