CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
- CISA KEV-listed (remediation due 2026-09-10)
- EPSS 0.3% (17.9% percentile)