What is CVE-2026-66380?
CVE-2026-66380 allows an authenticated user to access private OCI referrer metadata under specific conditions, even without repository read permission. This vulnerability could lead to the exposure of confidential information. Users are advised to apply security updates immediately.
Azərbaycanca: CVE-2026-66380 autentifikasiya olunmuş istifadəçiyə, xüsusi şərtlər altında, repozitoriy üzrə oxuma icazəsi olmadan belə özəl OCI referrer metadata-ya giriş imkanı verir. Bu zəiflik məxfi məlumatların sızmasına səbəb ola bilər. İstifadəçilərə dərhal təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Is authentication required to exploit CVE-2026-66380?
Yes, this vulnerability can only be exploited by an authenticated user under specific conditions.
What type of data can CVE-2026-66380 expose?
This vulnerability can lead to the exposure of private OCI referrer metadata and confidential information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.