CVE-2026-42016, a CVSS 8.1 authorization flaw in JFrog Artifactory Self-Hosted, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026 alongside a related flaw, CVE-2026-42018, in the same product. NVD’s vector shows a network-exploitable flaw requiring low privileges and no user interaction, with high impact to confidentiality and integrity.
What the vulnerability does
NVD tracks CVE-2026-42016 under CWE-863 (Incorrect Authorization). Per NVD’s description, JFrog Artifactory Self-Hosted versions before 7.133.11 are vulnerable to a privilege-escalation attack because the token validation logic checks a token’s signature and issuer but not its scope — meaning a token legitimately issued for a limited purpose can be used to gain broader access than it was scoped for.
Why it’s on KEV
CISA’s September 11 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Security vendor Wiz has published a blog post, titled to reference exploitation of both CVE-2026-42016 and CVE-2026-42018 together, describing “Artifactory under attack in the wild” (linked from NVD’s reference data for both CVEs) — evidence these two flaws are being chained or used interchangeably by attackers rather than treated as unrelated bugs.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone; we’re marking confidence medium on severity pending a second independent source. We don’t have an EPSS score for this CVE, nor granular data on which specific Artifactory deployment configurations (cloud vs. self-hosted, which permission models in use) are most exposed to the scope-validation gap.
Why this matters
Artifactory is a software supply-chain component — it stores and serves the build artifacts, container images, and packages an organization’s CI/CD pipeline depends on — so a privilege-escalation flaw there has downstream blast radius beyond the Artifactory instance itself: an attacker who escalates access could tamper with artifacts consumed by every downstream build. Because Wiz’s research and the shared KEV addition date tie CVE-2026-42016 to its sibling CVE-2026-42018 (an authentication flaw in the same product), organizations running any pre-7.133.11 Artifactory Self-Hosted instance should treat this as one combined upgrade, not two separate patch decisions.
Frequently Asked Questions
What is CVE-2026-42016? A CVSS 8.1 incorrect-authorization vulnerability in JFrog Artifactory Self-Hosted (before 7.133.11) that lets an attacker escalate privileges because token scope isn’t validated, only signature and issuer.
Is CVE-2026-42016 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026, and Wiz has published research describing in-the-wild exploitation.
Is this related to CVE-2026-42018? Yes — both affect JFrog Artifactory, were added to CISA KEV the same day, and are referenced together in Wiz’s exploitation research.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.