PT-2026-65102 · Jfrog · Artifactory

CVE-2026-42016

·

Published

2026-07-27

·

Updated

2026-09-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JFrog Artifactory (Self Hosted) versions prior to 7.133.11
Description An incorrect authorization validation of the user token allows for privilege escalation. The issue occurs because the system performs a validation check on the token signature and issuer but fails to validate the token's scope.
Recommendations Update JFrog Artifactory (Self Hosted) to version 7.133.11 or later.

Fix

LPE

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42016

Affected Products

Artifactory