CVE-2026-66014

EUVD-2026-49572
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.7%
Affected Products (NVD)
VendorProductVersion
jfrogartifactory
𝑥
< 7.111.18
jfrogartifactory
7.117.0 ≤
𝑥
< 7.117.25
jfrogartifactory
7.125.0 ≤
𝑥
< 7.125.18
jfrogartifactory
7.133.0 ≤
𝑥
< 7.133.27
jfrogartifactory
7.146.0 ≤
𝑥
< 7.146.34
jfrogartifactory
7.161.0 ≤
𝑥
< 7.161.15
𝑥
= Vulnerable software versions