← Vulnerability feed

Vulnerability record · CVE-2026-66384 · published 12 August 2026

CVE-2026-66384: JFrog Artifactory path traversal in Docker cache path

Jfrog · Artifactory

An authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The flaw is a path traversal (CWE-22) that breaks the intended directory restriction, allowing writes to locations the user should not control. It matters because integrity of files on the Artifactory host or shared storage can be altered by a low-privileged account, and CISA added it to KEV with a short remediation deadline.

5.3 CVSS 3.1 Medium CISA KEV since 27 Aug 2026 EPSS 0.66% · top 50.2% CWE-22 · Path traversal
5.3CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
28 Aug 2026Last modified by NVD

Description

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCISA KEV listing confirms known exploitation with a near-term remediation deadline, but the CVSS score is only 5.3 and impact is integrity-only with no ransomware use documented.

What it is

An authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The flaw is a path traversal (CWE-22) that breaks the intended directory restriction, allowing writes to locations the user should not control. It matters because integrity of files on the Artifactory host or shared storage can be altered by a low-privileged account, and CISA added it to KEV with a short remediation deadline.

Impact

An attacker with an authenticated account gains the ability to write files outside the Docker cache directory, corrupting or planting content on paths reachable by the Artifactory process. There is no confidentiality or availability impact per the CVSS vector; the effect is integrity-only.

Attack surface

Reached over the network through Artifactory's remote-repository handling, requiring a valid low-privileged authenticated account and specific remote-repository conditions. No user interaction is needed per the CVSS vector (UI:N).

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2026-08-27 with a 2026-09-10 due date, indicating known exploitation, though no ransomware campaign use is documented. EPSS is low (0.00579, 46th percentile), so the KEV listing is the stronger signal.

What to do

  • Apply the vendor fix from the JFrog Artifactory release notes and security advisories as the first action.
  • If patching cannot be completed before the CISA due date, restrict or disable remote-repository configurations that trigger the vulnerable Docker cache path handling.
  • Limit authenticated accounts that can configure or use remote repositories, and review who holds those permissions.
  • Follow CISA BOD 26-04 guidance for exposed or cloud-hosted instances, including discontinuing use if mitigations are unavailable.
  • Monitor JFrog advisories for updated fixed versions and re-check exposure after upgrading.

Detection

  • Audit Artifactory logs for writes to paths outside the configured Docker cache directory, especially traversal sequences in repository or path parameters.
  • Alert on remote-repository configuration changes and on Docker cache operations from accounts that do not normally perform them.
  • Use file integrity monitoring on Artifactory host and storage paths to catch unexpected file creation or modification.
  • Correlate authenticated Artifactory activity with outbound or lateral movement from the Artifactory host after suspicious writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-66384 to the Known Exploited Vulnerabilities catalog on 27 August 2026 as "JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 10 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-66384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2022-0668Jfrog artifactory improper privilege management vulnerabilityJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is…EPSS 0.63%9.8CVE-2019-17444JFrog Artifactory default admin passwords allow full compromiseJFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials …EPSS 69%analysed9.8CVE-2018-19971Jfrog artifactory insufficient verification of data authenticity vulnerabilityJFrog Artifactory Pro 6.5.9 has Incorrect Access Control.EPSS 3.0%9.8CVE-2019-9733JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-ForArtifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For…EPSS 53%analysed9.8CVE-2016-10036Jfrog artifactory unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…EPSS 26%

Source: NIST National Vulnerability Database (record CVE-2026-66384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.