CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

  • Published Jul 27, 2026
  • CVSS 8.8 high
  • 8.6% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A fix is available

Affected software

CVE-2026-42016 at the National Vulnerability Database