CVE-2026-66014
HIGH
8.8
CVSS 3.1
Description
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
Metadata
Severity & Metrics
8.8
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| jfrog | artifactory | — | 0 < 7.111.18, 7.117.0 < 7.117.25, 7.125.0 < 7.125.18, 7.133.0 < 7.133.27 … |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-287 | cna | CWE-287 Improper Authentication |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 8.8 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References (2)