CVE-2026-66378: Authenticated users may access private NuGet metadata
Published Aug 12, 2026
·Updated
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
Affected Software
3 affected components
nuget
JFrog Artifactory<7.146.35
JFrog Artifactory>=7.161.0<7.161.16
Event History
Aug 12, 2026
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-66378?
The severity of CVE-2026-66378 is medium with a score of 4.3.
2
What does CVE-2026-66378 exploit?
CVE-2026-66378 allows authenticated users without repository read permission to access private NuGet metadata under specific conditions.
3
How do I fix CVE-2026-66378?
To fix CVE-2026-66378, ensure that proper permissions are configured for users regarding access to NuGet metadata.
4
Who is affected by CVE-2026-66378?
Authenticated users of NuGet who do not have repository read permission may be affected by CVE-2026-66378.
5
What software is impacted by CVE-2026-66378?
CVE-2026-66378 impacts the NuGet software platform.