EXPOSURES › CVE-2026-66384
CVE-2026-66384
HIGH ⌖ ON CISA KEV · EXPLOITEDAn authenticated user can write data outside the intended Docker cache path in JFrog Artifactory under specific remote-repository conditions.
This path traversal vulnerability allows attackers to write files outside the intended Docker cache directory, potentially leading to arbitrary code execution or data exfiltration. DIB organizations must ensure Artifactory is patched and monitored for unauthorized file writes, as this could compromise build pipelines and supply-chain integrity.
Shame score — A known vulnerability in a widely used DevOps tool that allows authenticated attackers to escape intended boundaries, posing a significant supply-chain risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.