HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-42016 — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri...

·Source: NIST NVD

Updated:

Executive Summary

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Analysis

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. CVSS Score: 8.1. Published: 2026-07-27T20:16:39.613.

Indicators of Compromise (1)

CVE (1)
CVE-2026-42016
Source Attribution

Originally published by NIST NVD on Jul 27, 2026. Verified by: NIST.

Related Threats