CVE-2026-66375: Low-privilege users may remove protected Artifactory metadata
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure only trusted/high-privilege users can delete protected internal metadata in Artifactory repositories; restrict/delete permissions for low-privilege authenticated users to prevent permanent removal of protected metadata under the reported conditions.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66375?
The severity of CVE-2026-66375 is rated high, with a score of 8.1.
What does CVE-2026-66375 affect?
CVE-2026-66375 affects JFrog Artifactory, allowing low-privilege users to remove protected internal metadata.
How do I fix CVE-2026-66375?
To fix CVE-2026-66375, apply the latest security update provided by JFrog for Artifactory.
Who is affected by CVE-2026-66375?
Low-privilege authenticated users are affected by CVE-2026-66375 as they can exploit the vulnerability to remove protected metadata.
What are the consequences of CVE-2026-66375?
The consequences of CVE-2026-66375 include potential permanent loss of important metadata across repositories.