← back
CVE-2026-42016highunder attackCWE-863

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

51Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 8.1epss 9.1%
from disclosure to weapon
Published on NVDJul 27
CISA KEV+46d
exploitation probability
9.1%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2026-09-25

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

JFrog Artifactory fails to properly check user permissions when validating tokens, allowing attackers to gain higher privileges than they should have. This could let someone access or modify files they shouldn't be able to reach.

Technical detail

The vulnerability stems from improper authorization validation in JFrog Artifactory versions before 7.133.11, where the authentication mechanism validates token signature/issuer but fails to enforce token scope restrictions. An attacker with a valid token can escalate privileges by bypassing scope validation, potentially gaining unauthorized access to protected resources or administrative functions.

Summary generated and translated by AI from the official description.
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
jfrog · artifactory