Path Validation Weakness in JFrog Artifactory
CVE-2026-65921
8.8HIGH
What is CVE-2026-65921?
A path validation vulnerability in JFrog Artifactory's archive extraction and write handling functionality can be exploited to manipulate file paths. This weakness allows attackers to craft archive entries with traversal sequences, potentially writing files outside the designated build artifact location. This may lead to unauthorized access to sensitive data or alterations in the file structure, thus compromising the integrity of the application.
Affected Version(s)
artifactory 0 < 7.111.18
artifactory 7.117.0 < 7.117.25
artifactory 7.125.0 < 7.125.18
