Helm TLS Private Key Exposure in Rendered Manifests
CVE-2026-66016 Published on August 12, 2026
Rendered Artifactory Helm manifests may contain generated TLS private keys
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
Vulnerability Analysis
CVE-2026-66016 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Cleartext Storage of Sensitive Information
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Because the information is stored in cleartext, attackers could potentially read it. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Products Associated with CVE-2026-66016
Want to know whenever a new CVE is published for JFrog Artifactory? stack.watch will email you.
Affected Versions
jfrog artifactory:- Before 7.146.35 is affected.
- Version 7.161.0 and below 7.161.16 is affected.