JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Executive summary
Public reporting documents: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. This is public CTI and does not assess organizational exposure.
Technical analysis
The available public source describes JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. Technical details are limited to the cited source text and deterministic extracted records; unsupported attribution is excluded.
Evidence and sources
1 source document(s) and 1 evidence fragment(s) support this event; source publication and collection provenance are retained in the corpus.
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
IOCs
https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
https://nvd.nist.gov/vuln/detail/CVE-2026-66384
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
CVEs and affected products
Public-source record for CVE-2026-66384 in JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability.
ATT&CK mapping
No ATT&CK mapping is available.
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
0.85
⚠️ Public CTI only; no claim about organizational exposure.
⚠️ Detection logic is generic triage and requires environment-specific tuning.
⚠️ Provider enrichment and ATT&CK mapping are not asserted where unavailable.