CVE-2026-66380
EUVD-2026-5724412.08.2026, 15:18
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jfrog | artifactory | 𝑥 < 7.146.35 |
| jfrog | artifactory | 7.161.0 ≤ 𝑥 < 7.161.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration