AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66381

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A repository reader with cache-deploy permissions can exploit a vulnerability to access content beyond the designated upstream path, potentially leading to unauthorized data exposure. Organizations utilizing affected repository systems should prioritize remediation to mitigate the risk of sensitive information leakage. This is particularly relevant for environments where access controls are critical for maintaining data integrity and confidentiality.

CVE
CVE-2026-66381
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.