CVE-2026-66384

Published Aug 12, 2026

Last updated 9 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-66384 is identified as a path traversal vulnerability (CWE-22) affecting JFrog Artifactory. This flaw allows an authenticated user to write data outside of the designated Docker cache path. This can occur when specific remote-repository conditions are met within the Artifactory environment. The vulnerability stems from how JFrog Artifactory handles path construction for cached Docker artifacts retrieved through remote repositories. Under certain configurations, the input used to determine the cache path is not adequately normalized against traversal sequences, enabling an authenticated user with appropriate permissions to manipulate the write path. This results in files being written to arbitrary locations accessible by the Artifactory process, thereby undermining the integrity of files on the Artifactory server.

Description
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Source
reefs@jfrog.com
NVD status
Modified
Products
artifactory

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.3
Impact score
3.6
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Exploit added on
Aug 27, 2026
Exploit action due
Sep 10, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

reefs@jfrog.com
CWE-22

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

Configurations