[KEV] CVE-2026-66384 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-66384 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-66384 is a path traversal-style improper pathname restriction vulnerability in JFrog Artifactory that affects Docker remote-repository cache handling.
Technical Detail
The flaw does not adequately limit pathnames to the intended Docker cache directory under specific remote-repository conditions. An authenticated Artifactory user may be able to cause data to be written outside the intended Docker cache path. The documented impact is unauthorized file writing within the context and filesystem locations accessible to the affected Artifactory deployment; remote code execution, privilege escalation, and authentication bypass have not been confirmed.
Exploitation Status
Exploit maturity is operational, meaning exploitation methods are considered usable in practice rather than limited to a conceptual demonstration. CISA has confirmed active exploitation in the wild. This CVE was added to the CISA Known Exploited Vulnerabilities Catalog on August 27, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize applying JFrog-provided security updates or mitigations for affected Artifactory deployments, with particular attention to instances that use Docker remote repositories. CISA binding directive requirements call for federal civilian agencies to patch by September 17, 2026 or apply mitigations. Until remediation is complete, restrict Artifactory access to necessary authenticated users, review permissions for remote repository administration and Docker cache operations, and monitor Artifactory hosts for unexpected file writes or newly created files outside expected Docker cache directories. No vendor-specific workaround or definitive detection indicators are provided in the available information.