CyberRota Analysis
AI-GeneratedAuthenticated users lacking repository read permissions can exploit a vulnerability to access private OCI referrer metadata, potentially exposing sensitive information. This could lead to unauthorized data disclosure within affected systems. Organizations using OCI repositories should prioritize remediation to mitigate the risk of information leakage.
CVE
CVE-2026-66380
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Original NVD Description
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.