Path traversal in Artifactory - CVE-2026-66381
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to access content outside configured upstream paths.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in repository access controls when handling repository content requests. A remote user can request content outside a configured upstream path to access content outside configured upstream paths.
Exploitation requires repository read access together with cache-deploy permission.