CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Medium severity, CVSS 5.3. Actively exploited: in CISA KEV since 2026-08-27. EPSS: 0.7% chance of exploitation in the next 30 days.
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Affected products
- JFrog Artifactory: before 7.146.35 (fixed in 7.146.35); from 7.161.0, before 7.161.16 (fixed in 7.161.16)
Published 2026-08-12. Last modified 2026-08-28.