CVE-2026-42016

Published Jul 27, 2026

Last updated 15 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42016 is a privilege escalation vulnerability affecting JFrog Artifactory Self Hosted versions prior to 7.133.11. The flaw resides in the token validation logic, which correctly verifies the token's signature and issuer but fails to enforce the token's defined scope. This oversight allows an authenticated attacker, even with low-privileged access, to exploit a valid token to perform actions beyond their assigned permissions and escalate their privileges within an Artifactory deployment, potentially reaching administrative access. The vulnerability has been observed in active exploitation, often chained with other Artifactory flaws to bypass authentication and gain administrative control.

Description
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Source
reefs@jfrog.com
NVD status
Analyzed
Products
artifactory

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
JFrog Artifactory Incorrect Authorization Vulnerability
Exploit added on
Sep 11, 2026
Exploit action due
Sep 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

reefs@jfrog.com
CWE-863

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

13

  1. CISA added two JFrog Artifactory flaws, CVE-2026-42016 and CVE-2026-42018, after observed exploitation chained them for admin control of self-hosted servers. Fixes predated the attacks: patch exposed instances. https://t.co/uGvcp1TvcM #AppSec #KEV #AI #cybersecurity

    @RosettaLab

    12 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #schwachstellen JFrog Artifactory: CISA meldet aktive Ausnutzung von CVE-2026-42016 und CVE-2026-42018 #artifactory #cisa #cisabod2604 #cisakev #cve202642016 #cve202642018 #jfrog #jfrogartifactory #kev #nvd #privilegeescalation https://t.co/mKl3DGc4TX

    @cybsecuritynews

    12 Sept 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. News: JFrog Artifactory CVE-2026-42018 and CVE-2026-42016 let attackers mint admin JWTs and drop a Rust backdoor. Patch self-hosted to 7.111.21+; hunt rogue admins. https://t.co/L553OS6g0S

    @snakeyesV1

    12 Sept 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-42016, - 42018, - 82329: attackers are chaining three JFrog Artifactory flaws to gain full administrative control. Wiz observed attackers chaining an auth flaw (CVE-2026-42018) with a token scope-validation weakness (CVE-2026-42016) between August 15 and September 8 —

    @vuln_tracker

    12 Sept 2026

    161 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. JFrog Artifactory Token Validation Flaw Allows Privilege Escalation (CVE-2026-42016) A logic flaw in JFrog Artifactory token scope validation (CVE-2026-42016) lets low-privilege users escalate access. Patch… Full write-up → link in bio #cybersecurity #infosec #cve #kev #jfr

    @HotaSamit

    12 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🔒 #CyberSecurity CISA KEV Alert: CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory) and CVE-2026… "On September 11, 2026, CISA added three new entries to its Known Exploited Vulnerabilities…" 🔗 https://t.co/X1AfHct3vg #CyberSecurity #ThreatIntel #critical #zeroday #

    @SecurityAr58409

    12 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA put Artifactory on KEV. The two-bug chain is already live. @CISAgov listed CVE-2026-42016 and CVE-2026-42018 as Known Exploited on 11 Sep (federal due 25 Sep). @wiz_io watched multiple actors chain them against self-hosted @jfrog Artifactory from 15 Aug to 8 Sep: unauth

    @hackerlogs

    12 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706

    @__kokumoto

    12 Sept 2026

    869 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Attackers created admin accounts on exposed Artifactory instances by chaining CVE-2026-42018 and CVE-2026-42016. CVE-2026-42018 lets you pull JWTs for the internal anonymous user even with anonymous access turned off. CVE-2026-42016 then escalates via broken token validation.

    @SecureChap

    11 Sept 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSe

    @CISACyber

    11 Sept 2026

    6894 Impressions

    5 Retweets

    18 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  11. Attackers are chaining JFrog Artifactory flaws CVE-2026-42018 + CVE-2026-42016 to gain admin access and drop a Rust backdoor. Patch self-hosted instances now. #CyberSecurity #JFrog #InfoSec https://t.co/VcCewBlUr3

    @CyberWorldOps

    11 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. JFrog Artifactory flaws are being chained in the wild to mint admin tokens and plant a Rust backdoor on self-hosted servers. Wiz saw CVE-2026-42018 plus CVE-2026-42016 used Aug 15-Sep 8 to turn an anonymous JWT into admin in under five minutes, then install malicious Groovy

    @XavierRiveraX

    11 Sept 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.

    @Sunil_kumawat17

    11 Sept 2026

    71 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. #threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42

    @rst_cloud

    11 Sept 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB

    @yactina1336

    10 Sept 2026

    62 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations