High severity8.8NVD Advisory· Published Jul 27, 2026· Updated Sep 15, 2026
CVE-2026-66014
CVE-2026-66014
Description
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*+ 1 more
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*range: <7.111.18
- (no CPE)
Patches
Vulnerability mechanics
References
2- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease Notes
News mentions
4- JFrog Zero-Days Exploited in OpenAI-Hugging Face HackSecurityWeek · Jul 29, 2026
- Looks like JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security · Jul 28, 2026
- JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security · Jul 28, 2026
- OpenAI models used Artifactory zero-days to escape to the internetBleepingComputer · Jul 28, 2026