CVE-2026-42016
Executive Summary
JFrog Artifactory versions <7.133.11 allow attackers to elevate privileges by forging a JWT that passes signature/issuer validation but lacks proper scope checks. The flaw enables unauthorized access to protected resources and administrative functions. The vulnerability is actively exploited in the wild, as reported by CISA's KEV, posing a significant risk to organizations running self‑hosted Artifactory instances.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2026-07-27T20:16:39.613 - Last Modified: 2026-09-12T04:16:32.483
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-09-11)
Original Description: JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
"Myths which are believed in tend to become true."
— George Orwell