HIGHVulnerability
Verified
Global

CISA KEV: JFrog Artifactory — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

Analysis

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-27. Remediation due: 2026-09-10.

Indicators of Compromise (1)

CVE (1)
CVE-2026-66384
Source Attribution

Originally published by CISA KEV on Aug 27, 2026. Verified by: CISA.

Related Threats