{"id":"CVE-2026-42016","title":"Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation","summary":"JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cvssSource":"cna","cwe":["CWE-863"],"vendor":"jfrog","product":"artifactory","affected":["artifactory < 7.133.11"],"ssvc":{"exploitation":"active","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T00:00:00+00:00"},"exploited":true,"exploitAvailable":true,"published":"2026-07-27","updated":"2026-09-12","sourceUpdated":"2026-09-12T03:55:20.650Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-42016","references":[{"url":"https://docs.jfrog.com/releases/docs/jfrog-security-advisories"},{"url":"https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"}],"tags":["cve.org","in-the-wild","exploit-available","kev"],"epss":0.09058,"epssPercentile":0.95118,"kev":true,"kevDateAdded":"2026-09-11","kevDueDate":"2026-09-25","kevRansomware":false,"ingestedAt":"2026-09-14T15:23:07.483Z","slug":"CVE-2026-42016","body":"## Overview\n\nJFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.\n\n## Affected\n\n- `artifactory < 7.133.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":71,"depthScoreParts":{"impact":44.6,"likelihood":1.8,"exploitation":25,"ransomware":0},"changes":[{"seq":207748,"id":"CVE-2026-42016","ts":1789836592241,"field":"epss","old":"0.00886","new":"0.09058"},{"seq":183313,"id":"CVE-2026-42016","ts":1789354370314,"field":"kev","old":"false","new":"true"}]}