Critical Analysis: CVE-2026-66384 - JFrog Artifactory Improper Limitation of a Pathname to a Res... — September 2, 2026
Published 02 Sep 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
AGMP Partners Initial Discovery and Context Alright team, let’s talk about CVE-2026-66384. This one hit our radar this week, published on September 2, 2026, and it’s a classic case of improper limitation of a pathname to a restricted directory – a path traversal, or directory traversal, vulnerability affecting JFrog Artifactory. Now, Artifactory, as most of us know, is a mission-critical component in virtually every modern CI/CD pipeline, acting as a universal artifact repository manager. It stores everything from Docker images and Maven artifacts to npm packages and NuGet feeds. Its pervasive deployment within enterprise development ecosystems means any vulnerability impacting its integrity or availability carries significant weight, escalating its risk profile considerably. Our initial analysis indicates this flaw affects JFrog Artifactory versions 7.x.x prior to 7.82.5 and 6.x.x prior