AllCyberNews

CVE-2026-42016

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

CVSS 8.1 high · jfrog artifactory · published 2026-07-27

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Coverage 1 source

  1. 2026-09-11 CISA Cybersecurity Advisories critical CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA added three exploited vulnerabilities to its KEV Catalog: CVE-2026-42016, CVE-2026-42018, and CVE-2026-84869.

Mentioned with

CVE-2026-42018 CVE-2026-84869

Also covered