CVE-2026-66384
published 2026-08-12CVE-2026-66384: An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
PriorityP181medium5.3CVSS 3.1
AVNACHPRLUINSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-10
Exploited in the wild
EPSS
0.58%
45.7th percentile
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jfrog | artifactory | < 7.146.35 | 7.146.35 |
| jfrog | artifactory | >= 7.161.0 < 7.161.16 | 7.161.16 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
vulncheck5.3MEDIUM
cisa5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
JFrog Artifactory up to 7.146.34/7.161.15 out-of-bounds write
vuldb·2026-08-27·CVSS 5.3
CVE-2026-66384 [MEDIUM] JFrog Artifactory up to 7.146.34/7.161.15 out-of-bounds write
A vulnerability described as critical has been identified in JFrog Artifactory up to 7.146.34/7.161.15. This affects an unknown part. Such manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2026-66384. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
GHSA
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
ghsa_unreviewed·2026-08-12
CVE-2026-66384 [MEDIUM] CWE-22 An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
VulnCheck
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
vulncheck·2026·CVSS 5.3
CVE-2026-66384 [MEDIUM] CWE-22 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Affected: JFrog Artifactory
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's intern
CISA
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
cisa·2026-08-27·CVSS 5.3
CVE-2026-66384 [MEDIUM] CWE-22 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Vulnerability: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Affected: JFrog Artifactory
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each
No detection rules found.
No public exploits indexed.
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releaseshttps://docs.jfrog.com/releases/docs/jfrog-security-advisorieshttps://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdfhttps://openai.com/index/hugging-face-incident-and-the-road-ahead/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384
2026-08-12
Published
2026-08-27
Added to CISA KEV
Exploited in the wild