THREATOPS
THREAT OPSCVEs › CVE-2026-42016

CVE-2026-42016 — JFrog Artifactory Incorrect Authorization Vulnerability

CISA KEVExploited: confirmedJFrog

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Vulnerability details

Related reporting