CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path
CVSS Score
5.3
EPSS Score
0.3%
EPSS Percentile
18th
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
| CWE | CWE-22 |
| Vendor | jfrog |
| Product | artifactory |
| Published | Aug 12, 2026 |
| Last Updated | Aug 28, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for jfrog artifactory
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-66384.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
jfrog / artifactory
0 < 7.146.35 7.161.0 < 7.161.16
References
docs.jfrog.com: https://docs.jfrog.com/releases/docs/jfrog-security-advisories docs.jfrog.com: https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases cdn.openai.com: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf openai.com: https://openai.com/index/hugging-face-incident-and-the-road-ahead/ cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384
Credits
Kostya Kortchinsky | OpenAI