JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.
- Vendor
- JFrog
- Product
- Artifactory
- CVSS
- 8.1
- EPSS (exploit probability)
- 8.6%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
JFrog Artifactory validates a token’s signature and issuer but not its scope. An attacker who obtains a valid token, including one returned by the related anonymous-token flaw CVE-2026-42018, can present it with an elevated scope and gain unauthorized privileges.
CISA added CVE-2026-42016 to its Known Exploited Vulnerabilities catalog on September 11, 2026. Federal agencies must remediate by September 25, 2026. The JFrog advisory and NVD entry have version and patch details. Both Artifactory CVEs are being actively chained in ongoing attacks against self-managed Artifactory instances. The federal deadline is not the useful planning horizon for anyone running Artifactory on the open internet.
