CVE-2026-42016High· 8.1▾ Abyssal⚠ Exploited in the wildPoC availableJFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 44.6 · likelihood 1.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Federal remediation due Sep 25, 2026
0.3%
Last analysed / modified upstream
0.3% → 9.1%
Added to the CISA catalog on Sep 11, 2026. Federal remediation due Sep 25, 2026. View catalog ↗
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
artifactory < 7.133.11Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory
CVE-2026-69106High· 8.8A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-66014High· 8.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-69107Medium· 5.9An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-70547Medium· 4.3An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69105High· 8.1An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.