CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*

History

No history.

Information

Published : 2026-07-27 20:16

Updated : 2026-09-12 04:16


NVD link : CVE-2026-42016

Mitre link : CVE-2026-42016

CVE.ORG link : CVE-2026-42016


JSON object : View

Products Affected

jfrog

  • artifactory
CWE
CWE-863

Incorrect Authorization