Vulnerability
Published 2026-08-27
Verified 2026-09-19
JFrog Artifactory Docker cache path traversal (CVE-2026-66384)
Authenticated path-limitation flaw in JFrog Artifactory: under specific remote-repository conditions a user may write outside the intended Docker cache path. NVD affected builds end before 7.146.35, and 7.161.0 through builds before 7.161.16. CVSS 5.3. Patch to 7.146.35 or 7.161.16 (or later). Treat artifact caches as part of the software supply chain, not a side appliance.
- Product
- JFrog Artifactory
- Versions
- Before 7.146.35; 7.161.0 before 7.161.16
- CVSS
- (CVSS 3.1, NVD)
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- 7.146.35 or 7.161.16+
Primary: JFrog security advisories · Vendor: NVD · CVE: CVE-2026-66384 · Artifactory self-managed releases
