Medium severity5.3CISA KEVNVD Advisory· Published Aug 12, 2026· Updated Aug 28, 2026
CVE-2026-66384
CVE-2026-66384
Description
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease NotesVendor Advisory
- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- openai.com/index/hugging-face-incident-and-the-road-ahead/nvdThird Party Advisory
- cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdfnvdTechnical Description
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
6- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildSecurityWeek · Sep 1, 2026
- Hundreds of OpenAI Agents Invaded Hugging Face ServersDark Reading · Aug 28, 2026
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research BodyThe Hacker News · Aug 28, 2026
- OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own SystemsSecurityWeek · Aug 28, 2026
- JFrog Artifactory: 17 Vulnerabilities Disclosed, Highlighting Access Control and Metadata RisksVypr Intelligence · Aug 12, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts