VYPR
High severity8.1CISA KEVNVD Advisory· Published Jul 27, 2026· Updated Sep 12, 2026

CVE-2026-42016

CVE-2026-42016

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

8