Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-42016

JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory validates token signature and issuer but not scope, creating a privilege escalation path. CVSS 8.1 (high), CISA KEV deadline September 25, 2026.

cat cve-2026-42016.json
Vendor
JFrog
Product
Artifactory
CVSS
8.1
EPSS (exploit probability)
8.6%
Status
kev
CISA patch-by (BOD 22-01)
Published

JFrog Artifactory validates a token’s signature and issuer but not its scope. An attacker who obtains a valid token, including one returned by the related anonymous-token flaw CVE-2026-42018, can present it with an elevated scope and gain unauthorized privileges.

CISA added CVE-2026-42016 to its Known Exploited Vulnerabilities catalog on September 11, 2026. Federal agencies must remediate by September 25, 2026. The JFrog advisory and NVD entry have version and patch details. Both Artifactory CVEs are being actively chained in ongoing attacks against self-managed Artifactory instances. The federal deadline is not the useful planning horizon for anyone running Artifactory on the open internet.