CyberICT

CVE-2026-66014

Jfrog · Published July 27, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Affected Products

  • Artifactory < 7.111.18
  • Artifactory < 7.117.25
  • Artifactory < 7.125.18
  • Artifactory < 7.133.27

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H