← Back to CVE List
Vulnerability Intelligence Report
Authenticated users may write data outside the intended Docker cache path

CVE-2026-66384

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

CISA KEV SSVC: Active Exploitation Path Traversal
CVSS Base Score
5.3
MEDIUM
Exploitability:1.7
Impact Score:3.6
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory

Affected Products & Versions

Vendor Product Affected Versions
jfrog artifactory 0 < 7.146.35 (affected), 7.161.0 < 7.161.16 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.264%
Vulnerability Class
Path Traversal

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJFrog · Vendor · Israel
Reserved2026-07-25T11:29:31
Published2026-08-12T15:14:04
Last Updated2026-08-28T03:55:24

LINK COPIED TO CLIPBOARD