CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-09-11. EPSS: 8.6% chance of exploitation in the next 30 days.

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Affected products

  • JFrog Artifactory: before 7.133.11 (fixed in 7.133.11)

Published 2026-07-27. Last modified 2026-09-12.