Description
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Published: 2026-07-27
Score: 8.1 High
EPSS: 8.6% Low
KEV: Yes
Impact: Privilege Esc
Action: Immediate Patch
AI Analysis

Impact

JFrog Artifactory Self‑Hosted releases prior to 7.133.11 incorrectly validate user tokens by checking the signature and issuer but not the scope. This flaw permits an attacker who has a valid token to use it with higher privileges than intended, allowing access to protected artifacts, administrative functions and potentially compromising confidentiality, integrity, and availability of the system. The vulnerability is classified under CWE‑863, denoting an improper authorization weakness.

Affected Systems

All self‑hosted installations of JFrog Artifactory up to version 7.133.11 are affected. The flaw is tied to the token authentication logic used in those releases.

Risk and Exploitability

8.1 signals a high severity vulnerability, and the EPSS score of 9% indicates a moderate exploitation probability. It has now been listed in the CISA KEV catalog, indicating that the vulnerability has been observed in the wild or is considered a known exploit target.

Generated by OpenCVE AI on September 21, 2026 at 06:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest JFrog Artifactory update 7.133.11 or later to resolve the token scope validation issue
  • Implement an immediate interim check by whitelisting or restricting token scopes in the authentication configuration
  • Disable or replace the vulnerable token‑based authorization mechanism until the official patch is applied

Generated by OpenCVE AI on September 21, 2026 at 06:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

kev

{'dateAdded': '2026-09-11T00:00:00+00:00', 'dueDate': '2026-09-25T00:00:00+00:00'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Title Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-09-12T03:55:20.650Z

Reserved: 2026-04-23T13:41:13.754Z

Link: CVE-2026-42016

cve-icon Vulnrichment

Updated: 2026-07-27T20:17:12.428Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T20:16:39.613

Modified: 2026-09-12T04:16:32.483

Link: CVE-2026-42016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:45:10Z

Weaknesses