CVE-2016-10036: JFrog Artifactory
Critical severity, CVSS 9.8. EPSS: 25.2% chance of exploitation in the next 30 days.
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Affected products
- JFrog Artifactory: before 4.16 (fixed in 4.16)
Published 2018-05-01. Last modified 2026-06-17.