What is CVE-2026-66381?
CVE-2026-66381: A repository reader with `cache-deploy` permission may access content outside a configured upstream path under specific conditions. This could lead to unauthorized data exposure. Users are advised to apply security updates as soon as possible.
Azərbaycanca: CVE-2026-66381: `cache-deploy` icazəsi olan depo oxucusu, müəyyən şərtlər altında konfiqurasiya olunmuş upstream yolundan kənar məzmuna giriş əldə edə bilər. Bu, səlahiyyətsiz məlumat sızmasına səbəb ola bilər. İstifadəçilərin təhlükəsizlik yeniləməsini tətbiq etməsi tövsiyə olunur.
FAQ2
What permission must an attacker have to exploit CVE-2026-66381?
The attacker must be a repository reader with `cache-deploy` permission.
What can this vulnerability lead to?
It can lead to unauthorized data exposure due to accessing content outside a configured upstream path.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.