JFrogCVE-2026-66014
JFrog artifactory: privilege escalation
High8.8CVE-2026-66014 · Published Jul 27, 2026 · updated Sep 15, 2026
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| artifactory Product | < 7.111.18 | 7.111.18 |
| >= 7.117.0, < 7.117.25 | 7.117.25 | |
| >= 7.125.0, < 7.125.18 | 7.125.18 | |
| >= 7.133.0, < 7.133.27 | 7.133.27 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More JFrog advisories
All JFrog| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | JFrog artifactory: information disclosure | Medium6.5 | 7.146.34+1 more |
| Jul 27 | JFrog artifactory: server-side request forgery | Medium6.5 | 7.133.6 |
| Jul 27 | JFrog artifactory: path traversal | High8.8 | 7.111.18+3 more |
| Jul 27 | JFrog artifactory: missing authorization | High7.1 | 7.111.18+3 more |
| Jul 27 | JFrog artifactory: server-side request forgery | Medium6.8 | 7.111.18+3 more |
| Jul 27 | JFrog artifactory: server-side request forgery | Medium6.5 | 7.111.18+3 more |