CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Other sources
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66384?
The severity of CVE-2026-66384 is medium, rated at 5.3.
What type of vulnerability is CVE-2026-66384?
CVE-2026-66384 is classified as a Path Traversal vulnerability.
How does CVE-2026-66384 affect Docker?
CVE-2026-66384 allows authenticated users to write data outside the intended Docker cache path.
Who is affected by CVE-2026-66384?
Authenticated users with specific remote-repository conditions are affected by CVE-2026-66384.
How can I mitigate the risks associated with CVE-2026-66384?
To mitigate CVE-2026-66384, restrict user permissions and validate input paths in Docker configurations.