---
id: CVE-2026-66014
title: >-
  JFrog Artifactory contains an authentication handling weakness in internal
  request processing that, under specific conditions, may allow an attacker to
  escalate privileges beyond the intended access level.
summary: >-
  JFrog Artifactory contains an authentication handling weakness in internal
  request processing that, under specific conditions, may allow an attacker to
  escalate privileges beyond the intended access level.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: jfrog
product: artifactory
affected:
  - artifactory < 7.111.18
  - 'artifactory >= 7.117.0, < 7.117.25'
  - 'artifactory >= 7.125.0, < 7.125.18'
  - 'artifactory >= 7.133.0, < 7.133.27'
  - 'artifactory >= 7.146.0, < 7.146.34'
  - 'artifactory >= 7.161.0, < 7.161.15'
patched:
  - artifactory 7.161.15
published: '2026-07-27'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:30:26.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66014'
references:
  - url: 'https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases'
    label: reefs@jfrog.com
  - url: 'https://docs.jfrog.com/releases/docs/jfrog-security-advisories'
    label: reefs@jfrog.com
tags:
  - nvd
epss: 0.00635
epssPercentile: 0.49099
ingestedAt: '2026-09-15T18:41:59.120Z'
---

## Overview

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

## Affected

- `artifactory < 7.111.18`
- `artifactory >= 7.117.0, < 7.117.25`
- `artifactory >= 7.125.0, < 7.125.18`
- `artifactory >= 7.133.0, < 7.133.27`
- `artifactory >= 7.146.0, < 7.146.34`
- `artifactory >= 7.161.0, < 7.161.15`

## Remediation

Upgrade past the affected range:

- `artifactory 7.161.15`
