CVE-2026-66379
Puppet vulnerability analysis and mitigation

Overview

CVE-2026-66379 is a missing authorization vulnerability in JFrog Artifactory that allows any authenticated user to view private Puppet module metadata without having repository read access. Assigned by JFrog as a CVE Numbering Authority (CNA), it was published on August 12, 2026. Affected versions include all Artifactory releases prior to 7.146.35 and versions 7.161.0 through 7.161.15 (fixed in 7.161.16). It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, JFrog Advisories).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the Packages component of Artifactory fails to enforce repository read permissions when serving Puppet module metadata endpoints. An authenticated low-privilege user can send a network request to retrieve metadata for private Puppet repositories they are not authorized to access, bypassing the expected access control check. No special configuration is required for exposure; the vulnerability affects all standard Artifactory deployments running an affected version. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (GitHub Advisory, JFrog Self-Managed Releases).

Impact

Successful exploitation results in unauthorized disclosure of private Puppet module metadata to any authenticated Artifactory user, regardless of their assigned repository permissions. The confidentiality impact is limited to metadata (e.g., module names, versions, dependencies, authors) rather than full artifact content, and there is no impact on integrity or availability. In environments where Puppet module metadata contains sensitive organizational or infrastructure information, this exposure could aid reconnaissance or facilitate further attacks (JFrog Advisories, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. CISA's SSVC assessment (added August 13, 2026) classifies exploitation as "none" and the vulnerability as not automatable with only partial technical impact. The EPSS score is approximately 0.204% (11th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, JFrog Self-Managed Releases).

Exploitation steps

  1. Authentication: Obtain any valid low-privilege user account on the target JFrog Artifactory instance running an affected version (< 7.146.35 or 7.161.0–7.161.15).
  2. Identify Puppet repositories: Enumerate available Puppet repositories on the Artifactory instance, which may be partially visible through the UI or API even without read access.
  3. Request private metadata: Send an authenticated HTTP request to the Artifactory Puppet metadata endpoint for a private repository (e.g., GET /artifactory/api/puppet/<repo-name>/modules/<module-name>) using the low-privilege credentials.
  4. Retrieve metadata: Due to the missing authorization check, the server returns private Puppet module metadata (version info, dependencies, author details) without validating repository read permissions.
  5. Use metadata for reconnaissance: Leverage the exposed metadata to map internal infrastructure, identify software versions, or plan further targeted attacks (JFrog Self-Managed Releases, GitHub Advisory).

Indicators of compromise

  • Logs: Artifactory access logs showing authenticated users making repeated requests to Puppet metadata API endpoints (e.g., /api/puppet/) for repositories they do not have explicit read permissions on; unexpected 200 responses to such requests from low-privilege accounts.
  • Logs: Audit log entries showing access to private Puppet repository metadata by users with no configured read permissions on those repositories.
  • Network: Unusual volume of Puppet metadata API requests from a single authenticated user account, particularly targeting multiple private repositories in rapid succession.

Mitigation and workarounds

JFrog has addressed CVE-2026-66379 in Artifactory 7.161.16 (released August 12, 2026) and in versions 7.146.35 and later for the prior release train. Self-hosted users should upgrade to 7.146.35+ or 7.161.16+ as the primary remediation. As an interim measure, implement network-level access controls to restrict which authenticated users can reach Puppet metadata endpoints, and monitor audit logs for unauthorized access to private Puppet module metadata. Cloud (SaaS) environments managed by JFrog are not affected as they are updated automatically (JFrog Self-Managed Releases, JFrog Advisories).

Additional resources


SourceThis report was generated using AI

Related Puppet vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-5255HIGH7.5
  • Puppet logoPuppet
  • puppet
NoNoOct 03, 2023
CVE-2021-27025MEDIUM6.5
  • Ruby logoRuby
  • puppet
NoYesNov 18, 2021
CVE-2023-1894MEDIUM5.3
  • Puppet logoPuppet
  • libdb-utils-debuginfo
NoYesMay 04, 2023
CVE-2021-27026MEDIUM4.4
  • Puppet logoPuppet
  • puppet
NoYesNov 18, 2021
CVE-2026-66379MEDIUM4.3
  • Puppet logoPuppet
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management