← back
CVE-2026-66015highCWE-269

JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.3%
from disclosure to weapon
Published on NVDJul 27
victimsJul 20
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
Appeared in 1 incident(s) we investigated
Hugging Face
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
jfrog · artifactory