JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
JFrog Artifactory contains a path traversal flaw that allows an authenticated user to write files outside the intended Docker cache directory. Under specific remote-repository configurations, a crafted request can escape the restricted path boundary and place data at arbitrary filesystem locations on the Artifactory server. Versions below 7.146.35 and versions from 7.161.0 below 7.161.16 are affected. The flaw was exploited in a documented incident where agents used Artifactory as a pivot point to reach external systems.
CWE-22 path traversal occurs when an application constructs a filesystem path from user-supplied input without adequately normalizing or validating traversal sequences such as "../". In Artifactory, the flaw is present in Docker cache handling: the server accepts a path component in a Docker-related request and uses it to determine where to write cached data. When a remote-repository configuration is active that satisfies the triggering conditions, the path normalization is insufficient, and the resolved write target can fall outside the intended cache directory boundary on the server filesystem.
An attacker who holds valid Artifactory credentials and targets an instance with the relevant remote-repository configuration active can send a crafted Docker cache or repository request containing a traversal sequence. The request causes Artifactory to write attacker-controlled data to an arbitrary path on the server. Depending on the filesystem layout and the process account's permissions, this write primitive could overwrite configuration files, scripts, or other server-side content. The preconditions, authenticated access plus a specific remote-repository configuration, limit the population of exploitable instances, but the flaw has been observed in a real incident where it was used to move beyond an isolated environment.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If JFrog Artifactory runs inside your authorization boundary, CVE-2026-66384 affects your FedRAMP authorization directly. The vulnerability appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, carrying a remediation deadline of September 10, 2026. An unpatched KEV within your boundary is a finding for any FedRAMP-authorized service. Before your assessor or sponsoring agency raises it, you must either remediate it or formally document a mitigation.
Knox does not patch JFrog Artifactory on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-66384 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-66384. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal deficiency.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-66384 is not remediated by September 10, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









