AI description
CVE-2026-66384 is identified as a path traversal vulnerability (CWE-22) affecting JFrog Artifactory. This flaw allows an authenticated user to write data outside of the designated Docker cache path. This can occur when specific remote-repository conditions are met within the Artifactory environment. The vulnerability stems from how JFrog Artifactory handles path construction for cached Docker artifacts retrieved through remote repositories. Under certain configurations, the input used to determine the cache path is not adequately normalized against traversal sequences, enabling an authenticated user with appropriate permissions to manipulate the write path. This results in files being written to arbitrary locations accessible by the Artifactory process, thereby undermining the integrity of files on the Artifactory server.
- Description
- An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
- Source
- reefs@jfrog.com
- NVD status
- Modified
- Products
- artifactory
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 3.6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Exploit added on
- Aug 27, 2026
- Exploit action due
- Sep 10, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- reefs@jfrog.com
- CWE-22
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security. #CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384 https://t.co/Ne9C3Sf3er
@Daily_CyberSec
28 Aug 2026
170 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに以下3脆弱性を追加。 - CVE-2023-49105 (ownCloud) - CVE-2026-53362 (Linux Kernel) - CVE-2026-66384 (JFrog) 対処期限は上2件が3日後の8/30、J
@__kokumoto
27 Aug 2026
476 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 JFrog Artifactory'de Aktif İstismar Edilen Güvenlik Açığı JFrog Artifactory'de tespit edilen CVE-2026-66384, kimliği doğrulanmış kullanıcıların belirli uzak depo koşullarında Docker önbellek dizininin dışına veri yazmasına izin veren bir path traversal a
@rahmid3mir
27 Aug 2026
45 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added ownCloud vulnerability CVE-2023-49105, Linux kernel vulnerability CVE-2026-53362 & JFrog Artifactory vulnerability CVE-2026-66384 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity h
@CISACyber
27 Aug 2026
5336 Impressions
8 Retweets
30 Likes
2 Bookmarks
5 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "48E9C12E-B99B-4909-BB80-10D1AC6C9BF7",
"versionEndExcluding": "7.146.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "B21AF309-FD5B-4ACE-B407-8B3058D81500",
"versionEndExcluding": "7.161.16",
"versionStartIncluding": "7.161.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]