Authentication Bypass in JFrog Artifactory Affecting Unauthorized Users
CVE-2026-66380
4.3MEDIUM
What is CVE-2026-66380?
An authentication bypass vulnerability exists in JFrog Artifactory that could allow an authenticated user without the necessary repository read permission to access sensitive private OCI referrer metadata under specific circumstances. This may lead to unauthorized exposure of data intended to remain secure. Users of affected versions should evaluate their configuration and apply the recommended security measures to mitigate this risk.
Affected Version(s)
artifactory 0 < 7.146.35
artifactory 7.161.0 < 7.161.16
