Skip to content
JFrogCVE-2026-42016

JFrog artifactory: privilege escalation

High8.1CVE-2026-42016 · Published Jul 27, 2026 · updated Sep 12, 2026

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
< 7.133.117.133.11
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: information disclosure
Medium6.5Jul 27
JFrog artifactory: server-side request forgery
Medium6.5Jul 27
JFrog artifactory: path traversal
High8.8Jul 27
JFrog artifactory: missing authorization
High7.1Jul 27
JFrog artifactory: server-side request forgery
Medium6.8Jul 27
JFrog artifactory: server-side request forgery
Medium6.5Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.