Vulnerability record · CVE-2026-42016 · published 27 July 2026
CVE-2026-42016: JFrog Artifactory token scope bypass enables privilege escalation
Jfrog · Artifactory
JFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond what it was issued for. This is an incorrect authorization flaw that lets a low-privileged authenticated user escalate privileges within the instance.
Description
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and confirmed KEV listing including in-the-wild exploitation reports, though EPSS is modest and no ransomware use is documented.
What it is
JFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond what it was issued for. This is an incorrect authorization flaw that lets a low-privileged authenticated user escalate privileges within the instance.
Impact
An attacker with a valid low-privileged token gains unauthorized access to resources and actions outside the token's intended scope, with high impact to confidentiality, integrity and availability.
Attack surface
Reachable over the network via the Artifactory API or web interface using a token; the CVSS vector indicates low privileges are required and no user interaction. No unauthenticated path is described.
Exploitation
Listed in CISA KEV with a 2026-09-25 remediation due date, and a third-party advisory reference describes in-the-wild exploitation; EPSS 30-day probability is 0.00886 (57th percentile), so mass scanning is not indicated but targeted abuse is.
What to do
- Upgrade self-hosted Artifactory to 7.133.11 or later per the vendor release notes and security advisories.
- If immediate patching is not possible, restrict network access to the Artifactory instance and follow CISA BOD 26-04 guidance, including discontinuing use if no mitigation exists.
- Audit and rotate access tokens, revoking any tokens whose scope exceeds what the holder needs.
- Enforce least privilege on accounts and tokens that can reach the Artifactory API.
- Track the CISA KEV due date of 2026-09-25 and confirm remediation across all exposed instances.
Detection
- Review Artifactory audit and access logs for token-authenticated requests performing actions outside the token's expected scope or privilege level.
- Alert on privilege changes, permission grants, or administrative actions performed by low-privileged or service accounts.
- Monitor for anomalous API calls from tokens shortly after issuance or from unusual source addresses.
- Correlate Artifactory authentication events with downstream repository or configuration changes for signs of escalation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog on 11 September 2026 as "JFrog Artifactory Incorrect Authorization Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 25 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases | Release Notes |
| https://docs.jfrog.com/releases/docs/jfrog-security-advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016 | US Government Resource |
| https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 | Third Party Advisory |
Track CVE-2026-42016 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-42016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.