Missing Authorization in Artifactory - CVE-2026-66380
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in OCI referrer metadata access control when handling requests for private OCI referrer metadata. A remote user can send a request for private OCI referrer metadata to disclose sensitive information.
The issue affects authenticated users who do not have repository read permission.