Unauthorized Access Vulnerability in JFrog Artifactory
CVE-2026-66378
4.3MEDIUM
What is CVE-2026-66378?
An authenticated user who lacks the necessary repository read privileges can exploit a condition to gain access to private NuGet metadata in JFrog Artifactory. This flaw could potentially lead to exposure of sensitive information, posing significant risks to data integrity and confidentiality.
Affected Version(s)
artifactory 0 < 7.146.35
artifactory 7.161.0 < 7.161.16
