{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/jfrog/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-66384"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Artifactory"],"_cs_severities":["low"],"_cs_tags":["vulnerability","path-traversal","cisa-kev","jfrog","artifactory"],"_cs_type":"advisory","_cs_vendors":["JFrog"],"content_html":"\u003cp\u003eJFrog Artifactory contains a critical path traversal vulnerability (CVE-2026-66384) arising from an improper limitation of pathnames to a restricted directory. This vulnerability allows an authenticated attacker to bypass the intended security controls of the Docker cache path by leveraging specifically configured remote repositories. By manipulating the path parameters during repository interaction, an attacker can write data to arbitrary locations on the host file system. This flaw poses a significant risk to the integrity of the Artifactory host, as it may allow an attacker to overwrite configuration files, binary artifacts, or system files to achieve persistence or escalate privileges. Defenders should identify all instances of JFrog Artifactory, particularly those exposed to untrusted authentication sources, and apply vendor-provided patches or mitigations to prevent unauthorized file system modification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits an authenticated attacker to write files outside of the defined Docker cache directory. This capability can be leveraged to achieve code execution or persistence if an attacker replaces system binaries or configuration files. Organizations running self-managed instances of JFrog Artifactory are at highest risk, as the vulnerability directly impacts the host operating system's integrity. Given the inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog (BOD 26-04), timely remediation is mandated to mitigate the risk of host compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify and inventory all instances of JFrog Artifactory to assess versioning against the patched releases provided in the JFrog Security Advisories.\u003c/li\u003e\n\u003cli\u003eApply the security patches for CVE-2026-66384 as outlined in the JFrog self-managed release documentation.\u003c/li\u003e\n\u003cli\u003eEvaluate internet-facing instances of Artifactory and restrict access to remote repository configuration settings to highly trusted accounts only.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on the host systems running Artifactory to detect unauthorized modifications to configuration files or system directories.\u003c/li\u003e\n\u003cli\u003eComply with CISA BOD 26-04 requirements for vulnerability remediation and forensic triage as specified in the provided directive documentation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T21:04:52Z","date_published":"2026-08-27T21:04:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-jfrog-artifactory-path-traversal/","summary":"JFrog Artifactory suffers from a path traversal vulnerability that allows an authenticated user to write files to unauthorized locations on the server by manipulating remote-repository configurations.","title":"CVE-2026-66384 - Improper Path Limitation in JFrog Artifactory","url":"https://feed.craftedsignal.io/briefs/2026-08-jfrog-artifactory-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Jfrog","version":"https://jsonfeed.org/version/1.1"}