THREATOPS
THREAT OPSCVEs › CVE-2026-66384

CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

CISA KEVExploited: confirmedJFrog

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

Vulnerability details

Related reporting