MEDIUM
CVE-2026-66384
CVSS
5.3
KEV
Description
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
0.58%
Probability of exploitation in next 30 days
46.3th percentile
References
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
Release Notes, Vendor Advisory
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Vendor Advisory
https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
Technical Description
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-66384
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.