Status: NEW | Advisory ID: CVE-2026-66014
| CVE | CVE-2026-66014 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Classified as | CWE-287 (Improper Authentication) |
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
How to Fix Cloud Environment : Affected Cloud environments have already been fortified. No action is required for cloud instances. Self-Hosted Environment : Upgrade JFrog Artifactory to a fixed version applicable to your release branch: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-66014 |
| Vendor advisory | https://docs.jfrog.com/releases/docs/jfrog-security-advisories |