Vulnerability
Published 2026-08-27
Verified 2026-09-19

JFrog Artifactory Docker cache path traversal (CVE-2026-66384)

Authenticated path-limitation flaw in JFrog Artifactory: under specific remote-repository conditions a user may write outside the intended Docker cache path. NVD affected builds end before 7.146.35, and 7.161.0 through builds before 7.161.16. CVSS 5.3. Patch to 7.146.35 or 7.161.16 (or later). Treat artifact caches as part of the software supply chain, not a side appliance.

Product
JFrog Artifactory
Versions
Before 7.146.35; 7.161.0 before 7.161.16
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
7.146.35 or 7.161.16+

Primary: JFrog security advisories · Vendor: NVD · CVE: CVE-2026-66384 · Artifactory self-managed releases

vulnerabilities supply chain