
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66379 is a missing authorization vulnerability in JFrog Artifactory that allows any authenticated user to view private Puppet module metadata without having repository read access. Assigned by JFrog as a CVE Numbering Authority (CNA), it was published on August 12, 2026. Affected versions include all Artifactory releases prior to 7.146.35 and versions 7.161.0 through 7.161.15 (fixed in 7.161.16). It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, JFrog Advisories).
The root cause is classified as CWE-862 (Missing Authorization) — the Packages component of Artifactory fails to enforce repository read permissions when serving Puppet module metadata endpoints. An authenticated low-privilege user can send a network request to retrieve metadata for private Puppet repositories they are not authorized to access, bypassing the expected access control check. No special configuration is required for exposure; the vulnerability affects all standard Artifactory deployments running an affected version. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (GitHub Advisory, JFrog Self-Managed Releases).
Successful exploitation results in unauthorized disclosure of private Puppet module metadata to any authenticated Artifactory user, regardless of their assigned repository permissions. The confidentiality impact is limited to metadata (e.g., module names, versions, dependencies, authors) rather than full artifact content, and there is no impact on integrity or availability. In environments where Puppet module metadata contains sensitive organizational or infrastructure information, this exposure could aid reconnaissance or facilitate further attacks (JFrog Advisories, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. CISA's SSVC assessment (added August 13, 2026) classifies exploitation as "none" and the vulnerability as not automatable with only partial technical impact. The EPSS score is approximately 0.204% (11th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, JFrog Self-Managed Releases).
GET /artifactory/api/puppet/<repo-name>/modules/<module-name>) using the low-privilege credentials./api/puppet/) for repositories they do not have explicit read permissions on; unexpected 200 responses to such requests from low-privilege accounts.JFrog has addressed CVE-2026-66379 in Artifactory 7.161.16 (released August 12, 2026) and in versions 7.146.35 and later for the prior release train. Self-hosted users should upgrade to 7.146.35+ or 7.161.16+ as the primary remediation. As an interim measure, implement network-level access controls to restrict which authenticated users can reach Puppet metadata endpoints, and monitor audit logs for unauthorized access to private Puppet module metadata. Cloud (SaaS) environments managed by JFrog are not affected as they are updated automatically (JFrog Self-Managed Releases, JFrog Advisories).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."