THREAT OPS › CVEs › CVE-2026-42016
CVE-2026-42016 — JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Vulnerability details
- Affected productsArtifactory
- KEV remediation due2026-09-25
Related reporting
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVthehackernews
- [NVD] CVE-2026-42016 (HIGH 8.1) — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.nvd
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-42016 — JFrog Artifactory: JFrog Artifactory Incorrect Authorization Vulnerabilitycisa_kev
- Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329wiz_research