CyberRota Analysis
AI-GeneratedAuthenticated users lacking repository read permissions can exploit a vulnerability to access private NuGet metadata, potentially exposing sensitive information. Organizations that utilize NuGet for package management should prioritize addressing this issue to safeguard their private repositories and prevent unauthorized data access.
CVE
CVE-2026-66378
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Original NVD Description
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.