CVE-2026-65921
Potential path traversal leading to unauthorized file writes
Description
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
In plain language
AI Act nowCVE-2026-65921 is a serious file-writing flaw in JFrog Artifactory where a crafted archive can cause files to be written to unintended locations; typical small businesses that use Artifactory should treat this as urgent because real-world exploitation has been reported.
CVE-2026-65921 is a path traversal weakness (CWE-22) in JFrog Artifactory’s handling of untrusted archive uploads/extraction, enabling attackers to write files outside the intended directory (unauthorized file writes) by supplying crafted archive paths with traversal sequences; exploitation has been reported in the wild.
What to do now
- Check your JFrog Artifactory version and whether your setup accepts/uploads/extracts untrusted archive files.
- If you are on a version older than the fixes below, schedule an upgrade to one of the fixed versions: 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, or 7.161.15.
- After upgrading, verify the exact running Artifactory version matches the fixed release and confirm archive upload/extraction workflows still operate correctly.
- Review Artifactory activity logs around the time of any suspicious archive uploads and look for unusual file write or extraction behavior.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65921 and every CVE in our database. Create a free account — no credit card required.
Create Free Account