High severity8.1CISA KEVNVD Advisory· Published Jul 27, 2026· Updated Sep 12, 2026
CVE-2026-42016
CVE-2026-42016
Description
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*+ 1 more
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*range: <7.133.11
- (no CPE)range: <7.133.11
- Range: <7.133.11
Patches
Vulnerability mechanics
References
4- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201nvdThird Party Advisory
- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
8- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and RootkitsThe Hacker News · Sep 14, 2026
- Three JFrog Artifactory Flaws Exploited for Backdoor DeploymentSecurityWeek · Sep 14, 2026
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVThe Hacker News · Sep 12, 2026
- More JFrog Artifactory bugs under attack, and all 3 have patchesThe Register Security · Sep 11, 2026
- JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative ControlCyber Security News · Sep 11, 2026
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant BackdoorsThe Hacker News · Sep 11, 2026
- Jfrog: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Sep 11, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts