TLS Private Key Exposure Vulnerability in JFrog Artifactory
CVE-2026-66016
6.7MEDIUM
What is CVE-2026-66016?
In certain configurations of self-hosted Helm, there is a risk that generated TLS private keys may be inadvertently retained within rendered manifests. This exposure allows highly privileged local users to access sensitive cryptographic materials, increasing the risk of unauthorized access and potentially compromising the integrity of secure communications. Organizations using JFrog Artifactory should review their Helm deployment configurations to mitigate this risk.
Affected Version(s)
artifactory 0 < 7.146.35
artifactory 7.161.0 < 7.161.16
