AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66380

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated users lacking repository read permissions can exploit a vulnerability to access private OCI referrer metadata, potentially exposing sensitive information. This could lead to unauthorized data disclosure within affected systems. Organizations using OCI repositories should prioritize remediation to mitigate the risk of information leakage.

CVE
CVE-2026-66380
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.