JFrog disclosed CVE-2026-66015, a high-severity authorization flaw in the JFrog Platform that can let an authenticated user escalate privileges and obtain temporary platform administrator access under certain admin-provisioned account conditions. The issue is classified as CWE-269: Improper Privilege Management and carries a CVSS v3.1 score of 7.2.
The vulnerability affects JFrog Artifactory versions 7.146.0 through before 7.146.34 and 7.161.0 through before 7.161.15, according to the CVE record and JFrog's security advisories. Organizations running affected releases should review JFrog's advisory guidance and prioritize upgrades to fixed versions to prevent authenticated privilege escalation within the platform.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-66015 was published, classifying the issue as CWE-269 with a CVSS v3.1 score of 7.2. The record describes the flaw as an authorization weakness that may grant temporary platform administrator access.
JFrog disclosed CVE-2026-66015 as a high-severity authorization flaw in JFrog Platform/Artifactory that can allow authenticated privilege escalation under certain admin-provisioned account conditions. The advisory identifies affected versions as 7.146.0 before 7.146.34 and 7.161.0 before 7.161.15.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.