Path Traversal Vulnerability in JFrog Artifactory
CVE-2026-66381

5.3MEDIUM

Key Information:

Vendor

Jfrog

Vendor
CVE Published:
12 August 2026

What is CVE-2026-66381?

A security flaw exists in JFrog Artifactory that allows a repository reader with cache-deploy permissions to gain unauthorized access to content located outside of a specified upstream path. This vulnerability could potentially lead to information disclosure and the exposure of sensitive data, posing serious risks if exploited under certain configurations.

Affected Version(s)

artifactory 0 < 7.146.35

artifactory 7.161.0 < 7.161.16

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khai Tran | OpenAI
.