HIGH

CVE-2026-42016

Jfrog Artifactory 2026-07-27 CVSS v3.1
CVSS
8.8
KEV

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.89%
Probability of exploitation in next 30 days
57.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE