THREAT OPS › CVEs › CVE-2026-66384
CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Vulnerability details
- Affected productsArtifactory
- KEV remediation due2026-09-10
Related reporting
- August 2026 CVE Landscaperecordedfuture
- Critical Artifactory Bug Under Attackduo_decipher
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-66384 — JFrog Artifactory: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerabilitycisa_kev