← Terug naar overzicht

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory (path traversal) vulnerability tracked as CVE-2026-66384. The flaw allows an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog and is subject to BOD 26-04, which prioritizes security updates based on risk. JFrog has published security advisories and release notes for self-managed Artifactory instances addressing this issue. Organizations using JFrog Artifactory in self-managed deployments are advised to apply the relevant patches immediately. CISA has also provided forensics triage requirements as part of the BOD 26-04 implementation guidance. The NVD entry for this CVE provides additional technical details and scoring.

Affected products

  • JFrog Artifactory

Related CVE's

  • CVE-2026-66384

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Web Technologies