AI description
CVE-2026-42016 is a privilege escalation vulnerability affecting JFrog Artifactory Self Hosted versions prior to 7.133.11. The flaw resides in the token validation logic, which correctly verifies the token's signature and issuer but fails to enforce the token's defined scope. This oversight allows an authenticated attacker, even with low-privileged access, to exploit a valid token to perform actions beyond their assigned permissions and escalate their privileges within an Artifactory deployment, potentially reaching administrative access. The vulnerability has been observed in active exploitation, often chained with other Artifactory flaws to bypass authentication and gain administrative control.
- Description
- JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- Source
- reefs@jfrog.com
- NVD status
- Analyzed
- Products
- artifactory
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- JFrog Artifactory Incorrect Authorization Vulnerability
- Exploit added on
- Sep 11, 2026
- Exploit action due
- Sep 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- reefs@jfrog.com
- CWE-863
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
13
CISA added two JFrog Artifactory flaws, CVE-2026-42016 and CVE-2026-42018, after observed exploitation chained them for admin control of self-hosted servers. Fixes predated the attacks: patch exposed instances. https://t.co/uGvcp1TvcM #AppSec #KEV #AI #cybersecurity
@RosettaLab
12 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#schwachstellen JFrog Artifactory: CISA meldet aktive Ausnutzung von CVE-2026-42016 und CVE-2026-42018 #artifactory #cisa #cisabod2604 #cisakev #cve202642016 #cve202642018 #jfrog #jfrogartifactory #kev #nvd #privilegeescalation https://t.co/mKl3DGc4TX
@cybsecuritynews
12 Sept 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: JFrog Artifactory CVE-2026-42018 and CVE-2026-42016 let attackers mint admin JWTs and drop a Rust backdoor. Patch self-hosted to 7.111.21+; hunt rogue admins. https://t.co/L553OS6g0S
@snakeyesV1
12 Sept 2026
60 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-42016, - 42018, - 82329: attackers are chaining three JFrog Artifactory flaws to gain full administrative control. Wiz observed attackers chaining an auth flaw (CVE-2026-42018) with a token scope-validation weakness (CVE-2026-42016) between August 15 and September 8 —
@vuln_tracker
12 Sept 2026
161 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
JFrog Artifactory Token Validation Flaw Allows Privilege Escalation (CVE-2026-42016) A logic flaw in JFrog Artifactory token scope validation (CVE-2026-42016) lets low-privilege users escalate access. Patch… Full write-up → link in bio #cybersecurity #infosec #cve #kev #jfr
@HotaSamit
12 Sept 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CISA KEV Alert: CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory) and CVE-2026… "On September 11, 2026, CISA added three new entries to its Known Exploited Vulnerabilities…" 🔗 https://t.co/X1AfHct3vg #CyberSecurity #ThreatIntel #critical #zeroday #
@SecurityAr58409
12 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA put Artifactory on KEV. The two-bug chain is already live. @CISAgov listed CVE-2026-42016 and CVE-2026-42018 as Known Exploited on 11 Sep (federal due 25 Sep). @wiz_io watched multiple actors chain them against self-hosted @jfrog Artifactory from 15 Aug to 8 Sep: unauth
@hackerlogs
12 Sept 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706
@__kokumoto
12 Sept 2026
869 Impressions
1 Retweet
3 Likes
0 Bookmarks
1 Reply
0 Quotes
Attackers created admin accounts on exposed Artifactory instances by chaining CVE-2026-42018 and CVE-2026-42016. CVE-2026-42018 lets you pull JWTs for the internal anonymous user even with anonymous access turned off. CVE-2026-42016 then escalates via broken token validation.
@SecureChap
11 Sept 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSe
@CISACyber
11 Sept 2026
6894 Impressions
5 Retweets
18 Likes
1 Bookmark
1 Reply
0 Quotes
Attackers are chaining JFrog Artifactory flaws CVE-2026-42018 + CVE-2026-42016 to gain admin access and drop a Rust backdoor. Patch self-hosted instances now. #CyberSecurity #JFrog #InfoSec https://t.co/VcCewBlUr3
@CyberWorldOps
11 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JFrog Artifactory flaws are being chained in the wild to mint admin tokens and plant a Rust backdoor on self-hosted servers. Wiz saw CVE-2026-42018 plus CVE-2026-42016 used Aug 15-Sep 8 to turn an anonymous JWT into admin in under five minutes, then install malicious Groovy
@XavierRiveraX
11 Sept 2026
77 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.
@Sunil_kumawat17
11 Sept 2026
71 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42
@rst_cloud
11 Sept 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB
@yactina1336
10 Sept 2026
62 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
"versionEndExcluding": "7.133.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]