HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-42016 — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri...
·Source: NIST NVD
Updated:
Executive Summary
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Analysis
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. CVSS Score: 8.1. Published: 2026-07-27T20:16:39.613.