User Credential Persistence Issue in JFrog Artifactory
CVE-2026-66376

4.2MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-66376?

An issue has been identified in JFrog Artifactory where credentials for a user who has been deleted may remain valid for a limited duration. This can lead to potential unauthorized access, as these credentials do not immediately become inactive under certain conditions. Ensuring timely revocation of user credentials is critical to maintaining security integrity within the system.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Morris in collaboration with Claude and Anthropic Research
.