Access Control Vulnerability in JFrog Artifactory Affects User Permissions
CVE-2026-66379
4.3MEDIUM
What is CVE-2026-66379?
An authenticated user in JFrog Artifactory can gain unauthorized access to private Puppet module metadata, even without the required repository read permissions. This vulnerability exposes sensitive information that should be restricted, creating potential risks for organizations relying on identity management and access controls within the software.
Affected Version(s)
artifactory 0 < 7.146.35
artifactory 7.161.0 < 7.161.16
