Overview
What is CVE-2026-42016?
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
JFrog Artifactory Incorrect Authorization Vulnerability
CISA lists CVE-2026-42016 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to JFrog Artifactory.
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.