Junglewise Threat Intelligence

CVE-2026-66014: JFrog Artifactory privilege escalation in internal request processing

CVE-2026-66014 · Severity: high · CVSS 8.8 · Published 2026-07-27

Technologies: JFrog Artifactory Self-Managed. Vendors: JFrog.

Executive brief

JFrog Artifactory, a platform used by organizations to manage and store software building blocks (artifacts), contains a security flaw in how it handles internal requests. An attacker with basic user access could exploit this weakness to gain higher-level administrative permissions. This could allow unauthorized individuals to access sensitive software code, modify production packages, or disrupt the software delivery pipeline.

Technical details

JFrog Artifactory is vulnerable to improper authentication (CWE-287) within its internal request processing logic. The flaw allows a remote attacker with low-privileged credentials (PR:L) to bypass intended access controls and escalate their privileges to a higher level, potentially gaining administrative control over the platform. The vulnerability is reachable over the network without user interaction. JFrog has released several patched versions across different release branches, including 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15.

Affected products

  • JFrog Artifactory Self-Managed < 7.111.18, 7.117.0 to < 7.117.25, 7.125.0 to < 7.125.18, 7.133.0 to < 7.133.27, 7.146.0 to < 7.146.34, 7.161.0 to < 7.161.15

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory
  • 2026-07-27: patched: Fixed in Artifactory 7.161.15 and other maintenance releases.

References

Related threats