Missing Authorization in Artifactory - CVE-2026-66379
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Puppet module metadata access functionality when handling requests for private Puppet module metadata. A remote user can request metadata for a private Puppet module without repository read access to disclose sensitive information.