CVE-2026-66378: Authenticated users may access private NuGet metadata
Published Aug 12, 2026
·Updated
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
Affected Software
1 affected component
nuget
Event History
Aug 12, 2026
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66378?
The severity of CVE-2026-66378 is medium with a score of 4.3.
2
What does CVE-2026-66378 exploit?
CVE-2026-66378 allows authenticated users without repository read permission to access private NuGet metadata under specific conditions.
3
How do I fix CVE-2026-66378?
To fix CVE-2026-66378, ensure that proper permissions are configured for users regarding access to NuGet metadata.
4
Who is affected by CVE-2026-66378?
Authenticated users of NuGet who do not have repository read permission may be affected by CVE-2026-66378.
5
What software is impacted by CVE-2026-66378?
CVE-2026-66378 impacts the NuGet software platform.