CVE-2026-65921: Potential path traversal leading to unauthorized file writes
Published Jul 27, 2026
·Updated
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
Affected Software
6 affected components
JFrog Artifactory<7.111.18
JFrog Artifactory>=7.117.0<7.117.25
JFrog Artifactory>=7.125.0<7.125.18
JFrog Artifactory>=7.133.0<7.133.27
JFrog Artifactory>=7.146.0<7.146.34
JFrog Artifactory>=7.161.0<7.161.15
Event History
Jul 27, 2026
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65921?
CVE-2026-65921 has a severity rating of high at 8.8.
2
How do I fix CVE-2026-65921?
To fix CVE-2026-65921, ensure that all archive extraction and write handling processes validate file paths properly to prevent path traversal attacks.
3
What is the risk associated with CVE-2026-65921?
The risk associated with CVE-2026-65921 is rated as 79, indicating a significant potential threat to system integrity.
4
What software is affected by CVE-2026-65921?
CVE-2026-65921 affects JFrog Artifactory.
5
What type of vulnerability is CVE-2026-65921 classified as?
CVE-2026-65921 is classified as a Path Traversal vulnerability.