CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Summary
JFrog Artifactory has an improper limitation of a pathname to a restricted directory vulnerability. An authenticated user can exploit this to write data outside the intended Docker cache path under specific conditions. The vulnerability requires specific mitigations, with a federal due date of September 10, 2026.
IFF Assessment
This vulnerability allows authenticated users to write data outside of intended directories, potentially leading to unauthorized file manipulation or code execution, which is detrimental to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 10, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in JFrog Artifactory highlights the ongoing risk of path traversal issues even in widely used development and artifact management tools. Defenders should prioritize patching or applying mitigations for this and similar vulnerabilities affecting critical infrastructure. Keeping development and CI/CD pipelines secure is paramount to preventing supply chain attacks.