CVE-2026-66384
Published Aug 12, 2026
Last updated 16 days ago
AI description
CVE-2026-66384 is identified as a path traversal vulnerability (CWE-22) affecting JFrog Artifactory. This flaw allows an authenticated user to write data outside of the designated Docker cache path. This can occur when specific remote-repository conditions are met within the Artifactory environment. The vulnerability stems from how JFrog Artifactory handles path construction for cached Docker artifacts retrieved through remote repositories. Under certain configurations, the input used to determine the cache path is not adequately normalized against traversal sequences, enabling an authenticated user with appropriate permissions to manipulate the write path. This results in files being written to arbitrary locations accessible by the Artifactory process, thereby undermining the integrity of files on the Artifactory server.
- Description
- An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
- Source
- reefs@jfrog.com
- NVD status
- Analyzed
- Products
- artifactory
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 3.6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Exploit added on
- Aug 27, 2026
- Exploit action due
- Sep 10, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- reefs@jfrog.com
- CWE-22
- Hype score
- Not currently trending
🔴 CVE-2026-66384 | JFrog Artifactory | path traversal write | KEV 27 Aug Auth user writes outside Docker cache path under remote-repo conditions Supply-chain foothold next to AI model registries, treat as build-system compromise https://t.co/IkoLZrWHPk #CVE #KEV #SupplyCha
@PadhiyarRushi
2 Sept 2026
40 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
📢 JFrog Artifactory, la CISA alerte sur l’exploitation active de la vulnérabilité CVE-2026-66384 avec une échéance au 10 septembre 2026. Permet un contournement de la politique de sécurité #zoneantimalware https://t.co/QbI32uduPj
@NicolasCoolman
1 Sept 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-66384 — AI agents found a real vulnerability OpenAI AI agents discovered and exploited a JFrog Artifactory flaw during authorized security research. CVSS: 5.3 — but it's now in CISA KEV. https://t.co/TwprnMZmPN #CVE #AI #CyberSecurity #JFrog #OpenAI #InfoSec
@stem__shop
31 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added two flaws to KEV after OpenAI said its own AI agents exploited them: JFrog Artifactory 0-day CVE-2026-66384 and Linux kernel CVE-2026-53362. The agents found a public exploit, adapted it, got root. Patch now. #CyberSecurity #AppSec #OWASP https://t.co/b0sLORNuhu https
@OWASPHyderabad
29 Aug 2026
159 Impressions
2 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🔒 #CyberSecurity CISA KEV Alert: CVE-2026-66384 (JFrog Artifactory Path Traversal), CVE-2026-533… "On August 27, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities…" 🔗 https://t.co/SQ4ZuqjDyW #CyberSecurity #ThreatIntel #critical #zeroday
@SecurityAr58409
28 Aug 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-66384: JFrog Artifactory Path Traversal in Docker Cache — Detection an… "On August 27, 2026, CISA added CVE-2026-66384 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/P23huq8gCL #CyberSecurity #ThreatIntel #cve202666384 #critical
@SecurityAr58409
28 Aug 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CYBERSÉCURITÉ — JFROG ARTIFACTORY VISÉ PAR DES ATTAQUES La CISA confirme l’exploitation active de CVE-2026-66384, une vulnérabilité affectant JFrog Artifactory, plateforme largement utilisée pour stocker et distribuer les composants logiciels des entreprises. La
@ActuX_off
28 Aug 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security. #CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384 https://t.co/Ne9C3Sf3er
@Daily_CyberSec
28 Aug 2026
402 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに以下3脆弱性を追加。 - CVE-2023-49105 (ownCloud) - CVE-2026-53362 (Linux Kernel) - CVE-2026-66384 (JFrog) 対処期限は上2件が3日後の8/30、J
@__kokumoto
27 Aug 2026
700 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 JFrog Artifactory'de Aktif İstismar Edilen Güvenlik Açığı JFrog Artifactory'de tespit edilen CVE-2026-66384, kimliği doğrulanmış kullanıcıların belirli uzak depo koşullarında Docker önbellek dizininin dışına veri yazmasına izin veren bir path traversal a
@rahmid3mir
27 Aug 2026
51 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added ownCloud vulnerability CVE-2023-49105, Linux kernel vulnerability CVE-2026-53362 & JFrog Artifactory vulnerability CVE-2026-66384 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity h
@CISACyber
27 Aug 2026
7323 Impressions
10 Retweets
36 Likes
3 Bookmarks
5 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "48E9C12E-B99B-4909-BB80-10D1AC6C9BF7",
"versionEndExcluding": "7.146.35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "B21AF309-FD5B-4ACE-B407-8B3058D81500",
"versionEndExcluding": "7.161.16",
"versionStartIncluding": "7.161.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]