ctipilot.ch

JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV — a CI/CD artifact-store write primitive with no published exploitation narrative

cve · CVE-2026-66384

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
JFrog Artifactory

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-28/cve-2026-66384-jfrog-artifactory-docker-cache-traversal-kev · ATT&CK page ↗

Story timeline

  1. 2026-08-28JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV — a CI/CD artifact-store write primitive with no published exploitation narrative
    trending-vulnerabilitiesA Medium-severity Artifactory write bug just became a confirmed-exploited CI/CD supply-chain concern via KEV listing alone

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov1 (50%)
  • docs.jfrog.com1 (50%)

explore in graph

Entries about JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV — a CI/CD artifact-store write primitive with no published exploitation narrative (1)

2026-08-28 · view entry permalink →

NOTABLECVE-2026-66384exploitedNATOA2

JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV — a CI/CD artifact-store write primitive with no published exploitation narrative

CISA added CVE-2026-66384 to its Known Exploited Vulnerabilities catalog on 2026-08-27. Per JFrog's own advisory, published 2026-08-12 with a CVSS 3.1 base score of 5.3 Medium (CWE-22, Improper Limitation of a Pathname to a Restricted Directory): "an authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions" (JFrog Security Advisories, 2026-08-12) in Artifactory self-hosted below 7.146.35 and 7.161.0 through 7.161.16. Fixed in 7.146.35 and 7.161.16; JFrog states cloud environments were already remediated with no customer action required.

Neither JFrog's advisory nor CISA's KEV entry as surfaced this run describes the specific exploitation activity that justified the KEV addition — the only evidence available is the listing itself. That is a real gap in what can be said about this flaw, but the listing carries its own signal independent of the missing narrative: a KEV addition is CISA's own confirmation of active exploitation, a jurisdiction-agnostic fact distinct from any US-FCEB remediation deadline. Given Artifactory's role as a binary/artifact repository sitting inside CI/CD release pipelines, a write primitive that escapes the intended cache path is a software-supply-chain concern regardless of its Medium base score and authentication requirement — an attacker able to plant or overwrite files outside the sandboxed cache location could potentially influence what a downstream build or deployment consumes, even though the authentication requirement and Medium score keep this below the severity of an unauthenticated critical.

actions[] above is intentionally narrow: with no exploitation narrative to derive a specific compromise-check from, the do-now task is the upgrade itself, not a speculative hunt. Triage: none is offered for the same reason no additional detection guidance appears here — inventing a hunt query without a described exploitation mechanism would be fabrication; the durable step is patching and, where the environment allows it, reviewing Docker-cache directory contents for files outside their expected repository paths as a general compromise-assessment measure.

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

JFrog (Security Advisories) 2026-08-12
vulnerability28 Aug 05:50Zmulti-sourceOpen finding ↗