Access Control Vulnerability in JFrog Artifactory Affects User Permissions
CVE-2026-66379

4.3MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-66379?

An authenticated user in JFrog Artifactory can gain unauthorized access to private Puppet module metadata, even without the required repository read permissions. This vulnerability exposes sensitive information that should be restricted, creating potential risks for organizations relying on identity management and access controls within the software.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khai Tran | OpenAI
.