CVE-2026-66014

High8.8Published on July 27, 2026

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

CVSS score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-287
Vendorsjfrog

Affected products

VendorsProductVersions
jfrogartifactory< 7.111.18

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database