CVE-2026-66376: Deleted users may temporarily retain access to JFrog Artifactory
Published Aug 12, 2026
·Updated
Credentials for a deleted user may remain valid for a short period under specific conditions.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 12, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66376?
The severity of CVE-2026-66376 is medium with a score of 4.2.
2
How do I fix CVE-2026-66376?
To fix CVE-2026-66376, ensure that proper user deletion procedures are followed and regularly audit user access.
3
What vulnerabilities are associated with CVE-2026-66376?
CVE-2026-66376 is associated with risk due to deleted users retaining access credentials temporarily.
4
What software is affected by CVE-2026-66376?
CVE-2026-66376 affects JFrog Artifactory.
5
What are the conditions for CVE-2026-66376 to occur?
CVE-2026-66376 occurs under specific conditions where credentials for a deleted user can remain valid.