TLS Private Key Exposure Vulnerability in JFrog Artifactory
CVE-2026-66016

6.7MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-66016?

In certain configurations of self-hosted Helm, there is a risk that generated TLS private keys may be inadvertently retained within rendered manifests. This exposure allows highly privileged local users to access sensitive cryptographic materials, increasing the risk of unauthorized access and potentially compromising the integrity of secure communications. Organizations using JFrog Artifactory should review their Helm deployment configurations to mitigate this risk.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthew Bryant | OpenAI
.