CVE-2026-66014

Summary

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Affected Software

VendorProductVersion RangeStatus
jfrogartifactory0 < 7.111.18affected
jfrogartifactory7.117.0 < 7.117.25affected
jfrogartifactory7.125.0 < 7.125.18affected
jfrogartifactory7.133.0 < 7.133.27affected
jfrogartifactory7.146.0 < 7.146.34affected
jfrogartifactory7.161.0 < 7.161.15affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References