CVE-2026-66014

EUVD-2026-49572
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
JFROGCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jfrogartifactory
𝑥
< 7.111.18
CNA
jfrogartifactory
7.117.0 ≤
𝑥
< 7.117.25
CNA
jfrogartifactory
7.125.0 ≤
𝑥
< 7.125.18
CNA
jfrogartifactory
7.133.0 ≤
𝑥
< 7.133.27
CNA
jfrogartifactory
7.146.0 ≤
𝑥
< 7.146.34
CNA
jfrogartifactory
7.161.0 ≤
𝑥
< 7.161.15
CNA