JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
References
| Link | Resource |
|---|---|
| https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases | Release Notes |
| https://docs.jfrog.com/releases/docs/jfrog-security-advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016 | US Government Resource |
| https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-27 20:16
Updated : 2026-09-12 04:16
NVD link : CVE-2026-42016
Mitre link : CVE-2026-42016
CVE.ORG link : CVE-2026-42016
JSON object : View
Products Affected
jfrog
- artifactory
CWE
CWE-863
Incorrect Authorization
