SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-42016

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

JFrog Artifactory (Self Hosted) versions prior to 7.133.11 are susceptible to a privilege escalation vulnerability stemming from inadequate validation of token signatures and issuers, allowing attackers to exploit token scopes. This could enable unauthorized access to sensitive resources and functionalities within the application. Organizations using affected versions should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-42016
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Related CVEs

Other vulnerabilities affecting the same vendor(s)