Back to overview

CVE-2026-66014

HIGH
8.8
CVSS 3.1
Description
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Metadata

CVE ID
CVE-2026-66014
State
PUBLISHED
Assigner
JFROG
Reserved
2026-07-23 19:59 UTC
Published
2026-07-27 19:29 UTC
Last updated
2026-07-27 20:15 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication
Vendor / Product
jfrog / artifactory
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
jfrog artifactory 0 < 7.111.18, 7.117.0 < 7.117.25, 7.125.0 < 7.125.18, 7.133.0 < 7.133.27 …
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287 Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview