← All Advisories

An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access

Status: NEW  |  Advisory ID: CVE-2026-66014

Key Details

CVECVE-2026-66014
CVSS Score / Version8.8 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-287 (Improper Authentication)

What to Know

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

What to Do

How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-66014
Vendor advisoryhttps://docs.jfrog.com/releases/docs/jfrog-security-advisories