← back
CVE-2026-66014highCWE-287

Potential authentication bypass leading to privilege escalation in Artifactory

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.3%
from disclosure to weapon
Published on NVDJul 27
victimsJul 20
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
Appeared in 1 incident(s) we investigated
Hugging Face
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
jfrog · artifactory