CVE-2016-10036: JFrog Artifactory

Critical severity, CVSS 9.8. EPSS: 25.2% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.

Affected products

  • JFrog Artifactory: before 4.16 (fixed in 4.16)

Published 2018-05-01. Last modified 2026-06-17.