5.3

CVE-2026-66384

Warnung
Medienbericht

Authenticated users may write data outside the intended Docker cache path

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jfrog ≫ Artifactory SwPlatform - Version < 7.146.35
Jfrog ≫ Artifactory SwPlatform - Version >= 7.161.0 < 7.161.16
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

27.08.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

Schwachstelle

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
reefs@jfrog.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
28.08.2026 20:33
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Vendor Advisory
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
Vendor Advisory
Release Notes
https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
Technical Description
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384
US Government Resource