AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66378

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated users lacking repository read permissions can exploit a vulnerability to access private NuGet metadata, potentially exposing sensitive information. Organizations that utilize NuGet for package management should prioritize addressing this issue to safeguard their private repositories and prevent unauthorized data access.

CVE
CVE-2026-66378
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.