Hermes CTI

← Back to all reports

public_cti_event new

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

● HIGH Confidence: 85% · Version 1

Executive summary

Public reporting documents: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. This is public CTI and does not assess organizational exposure.

Technical analysis

The available public source describes JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. Technical details are limited to the cited source text and deterministic extracted records; unsupported attribution is excluded.

Evidence and sources

1 source document(s) and 1 evidence fragment(s) support this event; source publication and collection provenance are retained in the corpus.

Verified Evidence Claims

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability. JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

100% Confidence Analysis 🔍

IOCs

CVEs and affected products

Public-source record for CVE-2026-66384 in JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability.

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Public source publication: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

Confidence and caveats

0.85

⚠️ Public CTI only; no claim about organizational exposure.

⚠️ Detection logic is generic triage and requires environment-specific tuning.

⚠️ Provider enrichment and ATT&CK mapping are not asserted where unavailable.