• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-42016: authorization privilege escalation in JFrog Artifactory

A low-privileged network attacker can escalate privileges on JFrog Artifactory by exploiting an incorrect authorization check that validates token signature/issuer but not token scope; this is CVE-2026-42016. The flaw affects Artifactory 7.x before 7.133.11. An attacker needs network access to the service and a valid low-privilege account on an affected instance to trigger the issue.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.08643
CWE
CWE-863
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this vulnerability to its KEV catalog with a remediation due date, signalling immediate prioritization; apply the vendor fix or mitigations without delay for internet-facing Artifactory instances.

What is CVE-2026-42016?

A low-privileged network attacker can escalate privileges on JFrog Artifactory by exploiting an incorrect authorization check that validates token signature/issuer but not token scope; this is CVE-2026-42016. The flaw affects Artifactory 7.x before 7.133.11. An attacker needs network access to the service and a valid low-privilege account on an affected instance to trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of JFrog Artifactory are affected?

BRANCHAFFECTEDFIXED
7.xbefore 7.133.117.133.11

Is CVE-2026-42016 being exploited?

CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog on 2026-09-11, and U.S. federal agencies were required to remediate it by 2026-09-25.

How to fix CVE-2026-42016

  1. Upgrade Artifactory 7.x to 7.133.11.
  2. If you cannot upgrade immediately, restrict network exposure of Artifactory and limit reachable accounts.
  3. Follow JFrog’s vendor guidance and apply any recommended configuration mitigations.
  4. Monitor authentication and privilege-change logs for signs of misuse.

Frequently asked questions

Is CVE-2026-42016 being actively exploited?

CISA added CVE-2026-42016 to its Known Exploited Vulnerabilities catalog on 2026-09-11, and federal agencies were required to remediate it by 2026-09-25.

Which Artifactory versions are affected by CVE-2026-42016?

Artifactory 7.x versions before 7.133.11 are affected by CVE-2026-42016.

Is there a patch for CVE-2026-42016?

Yes. JFrog fixed the issue in Artifactory 7.133.11; upgrade to 7.133.11.

Does CVE-2026-42016 require authentication?

Yes. Exploitation requires a valid low-privilege account on the affected Artifactory instance.

References