CVE-2026-66016

EUVD-2026-57259
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
JFROGCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jfrogartifactory
𝑥
< 7.146.35
CNA
jfrogartifactory
7.161.0 ≤
𝑥
< 7.161.16
CNA