Insufficient Session Expiration in Artifactory - CVE-2026-66376
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to retain access after account deletion.
The vulnerability exists due to insufficient session expiration in user session handling when processing requests after a user account has been deleted. A remote user can continue using previously valid credentials to retain access after account deletion.
This occurs only for a short period under specific conditions.