Missing Authorization in Artifactory - CVE-2026-66375
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to remove protected internal metadata across repositories.
The vulnerability exists due to missing authorization in metadata protection mechanisms when handling authenticated repository operations. A remote user can delete protected internal metadata to remove protected internal metadata across repositories.