Skip to content
COOEY

EXPOSURES › CVE-2026-66384

CVE-2026-66384

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-66384 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedsupply-chain

An authenticated user can write data outside the intended Docker cache path in JFrog Artifactory under specific remote-repository conditions.

This path traversal vulnerability allows attackers to write files outside the intended Docker cache directory, potentially leading to arbitrary code execution or data exfiltration. DIB organizations must ensure Artifactory is patched and monitored for unauthorized file writes, as this could compromise build pipelines and supply-chain integrity.

Shame score — A known vulnerability in a widely used DevOps tool that allows authenticated attackers to escape intended boundaries, posing a significant supply-chain risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.