CVE-2026-66384 carries a CVSS 3.1 base score of 5.3 against JFrog Artifactory. NVD and CISA’s own KEV entry both classify it as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 27, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.
Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.
What the flaw is
NVD’s description for this CVE is brief: an authenticated user may write data outside the intended Docker cache path, under specific remote-repository conditions. NVD does not specify the exact conditions or code path involved beyond that summary.
Notably, NVD’s own reference list for this CVE points to OpenAI’s published technical incident report and blog post on what OpenAI itself has publicly termed the “Hugging Face Incident.” We have not independently reviewed that report’s full contents, so we are not characterizing its findings here beyond noting that it exists as a primary source OpenAI chose to publish, and that NVD ties it to this CVE. Readers wanting the technical detail of that incident should consult OpenAI’s own report directly.
Evidence and confidence
- High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated August 27, 2026.
- Medium confidence — the CVSS 5.3 score and vector (
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N), which trace to NVD alone in our current ingestion. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00579, a 45.8th percentile score as of our ingestion.
No field is in conflict between our sources. Our source data does not carry a fixed-version field; JFrog’s own release and security-advisory documentation pages are cited in NVD’s reference list as the authoritative source for patched versions.
Why this matters
A path-traversal flaw in an artifact repository’s Docker cache handling is a supply-chain-relevant bug by construction: Artifactory instances sit in the pipeline between where container images and packages are stored and where they are pulled for build and deployment, so a write that escapes its intended cache boundary can plant or corrupt content that downstream consumers later trust as legitimate. That this CVE is tied to a real, publicly documented incident — rather than a purely theoretical finding — is itself the strongest signal of its practical severity, independent of the moderate CVSS score.
Frequently Asked Questions
What is CVE-2026-66384? A CVSS 5.3 path traversal vulnerability (CWE-22) in JFrog Artifactory that lets an authenticated user write data outside the intended Docker cache path under specific remote-repository conditions.
Is CVE-2026-66384 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated August 27, 2026.
Do I need an account to exploit this? Yes. NVD’s description specifies this requires an authenticated user — it is not exploitable by a fully unauthenticated party.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.
Is a fixed version available? Our source data does not carry a specific fixed-version number. Consult JFrog’s own security advisories page and self-managed release notes for the current patched version.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-66384. Exploitation status and the August 27, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Incident context: OpenAI’s technical report and accompanying blog post. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.