Knox CVE Database
/
CVE-2026-66384
Medium
5.3

CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

Added to the CISA KEV catalog:
August 27, 2026

Overview

JFrog Artifactory contains a path traversal flaw that allows an authenticated user to write files outside the intended Docker cache directory. Under specific remote-repository configurations, a crafted request can escape the restricted path boundary and place data at arbitrary filesystem locations on the Artifactory server. Versions below 7.146.35 and versions from 7.161.0 below 7.161.16 are affected. The flaw was exploited in a documented incident where agents used Artifactory as a pivot point to reach external systems.

Vulnerability details

Affected vendor
JFrog
Affected product
Artifactory
Weakness type (CWE)
CWE-22

CWE-22 path traversal occurs when an application constructs a filesystem path from user-supplied input without adequately normalizing or validating traversal sequences such as "../". In Artifactory, the flaw is present in Docker cache handling: the server accepts a path component in a Docker-related request and uses it to determine where to write cached data. When a remote-repository configuration is active that satisfies the triggering conditions, the path normalization is insufficient, and the resolved write target can fall outside the intended cache directory boundary on the server filesystem.


An attacker who holds valid Artifactory credentials and targets an instance with the relevant remote-repository configuration active can send a crafted Docker cache or repository request containing a traversal sequence. The request causes Artifactory to write attacker-controlled data to an arbitrary path on the server. Depending on the filesystem layout and the process account's permissions, this write primitive could overwrite configuration files, scripts, or other server-side content. The preconditions, authenticated access plus a specific remote-repository configuration, limit the population of exploitable instances, but the flaw has been observed in a real incident where it was used to move beyond an isolated environment.

Severity and impact

5.3
Medium
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
None
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit Artifactory access logs for requests to Docker or remote-repository endpoints where the path parameter contains encoded or literal traversal sequences ("../", "%2e%2e", "%2f") outside the expected cache path structure.
  • Monitor the Artifactory server filesystem for new or modified files in directories outside the configured Docker cache root, particularly in configuration, binary, or startup directories, which have no legitimate write path from normal repository operations.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 10, 2026

Additional hardening

  • Upgrade Artifactory to 7.146.35 or later for the 7.146.x release line, or to 7.161.16 or later for the 7.161.x release line; see the vendor advisory in References for full version guidance.
  • Restrict Artifactory user accounts to the minimum required permissions; accounts that do not need Docker push or remote-repository write access should have those permissions removed, reducing the pool of credentials that can trigger the flaw.
  • Where possible, place Artifactory behind a network control that limits which hosts can authenticate and submit Docker or repository requests, reducing exposure to compromised or low-privilege credentials from unexpected sources.
  • Audit active remote-repository configurations and disable any that are not operationally required, as the vulnerability requires specific remote-repository conditions to be active on the target instance.

Key dates

Published (NVD)
August 12, 2026
Added to CISA KEV
August 27, 2026
Remediation deadline
September 10, 2026
Last updated
August 28, 2026

References

Frequently asked questions

Does CVE-2026-66384 affect my FedRAMP authorization?

If JFrog Artifactory runs inside your authorization boundary, CVE-2026-66384 affects your FedRAMP authorization directly. The vulnerability appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, carrying a remediation deadline of September 10, 2026. An unpatched KEV within your boundary is a finding for any FedRAMP-authorized service. Before your assessor or sponsoring agency raises it, you must either remediate it or formally document a mitigation.

How does Knox help me handle CVE-2026-66384?

Knox does not patch JFrog Artifactory on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-66384 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-66384. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal deficiency.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-66384 isn't remediated by September 10, 2026?

If CVE-2026-66384 is not remediated by September 10, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting