Skip to main content
QUIETLYTIC
Vulnerability

JFrog Artifactory Self-Hosted Privilege Escalation (CVE-2026-42016)

CVE-2026-42016 lets attackers escalate privileges in JFrog Artifactory via a token-scope validation gap. CISA added it to KEV Sept. 11, 2026; Wiz reports in-the-wild exploitation.

CVE-2026-42016
Threat Level
HIGH
CVSS
8.1
Status
Active Exploitation
Confidence
Medium
Affected Products
JFrog Artifactory Self-Hosted (before 7.133.11)

CVE-2026-42016, a CVSS 8.1 authorization flaw in JFrog Artifactory Self-Hosted, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026 alongside a related flaw, CVE-2026-42018, in the same product. NVD’s vector shows a network-exploitable flaw requiring low privileges and no user interaction, with high impact to confidentiality and integrity.

What the vulnerability does

NVD tracks CVE-2026-42016 under CWE-863 (Incorrect Authorization). Per NVD’s description, JFrog Artifactory Self-Hosted versions before 7.133.11 are vulnerable to a privilege-escalation attack because the token validation logic checks a token’s signature and issuer but not its scope — meaning a token legitimately issued for a limited purpose can be used to gain broader access than it was scoped for.

Why it’s on KEV

CISA’s September 11 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Security vendor Wiz has published a blog post, titled to reference exploitation of both CVE-2026-42016 and CVE-2026-42018 together, describing “Artifactory under attack in the wild” (linked from NVD’s reference data for both CVEs) — evidence these two flaws are being chained or used interchangeably by attackers rather than treated as unrelated bugs.

What we don’t yet have

CVSS scoring and the vulnerability description trace to NVD alone; we’re marking confidence medium on severity pending a second independent source. We don’t have an EPSS score for this CVE, nor granular data on which specific Artifactory deployment configurations (cloud vs. self-hosted, which permission models in use) are most exposed to the scope-validation gap.

Why this matters

Artifactory is a software supply-chain component — it stores and serves the build artifacts, container images, and packages an organization’s CI/CD pipeline depends on — so a privilege-escalation flaw there has downstream blast radius beyond the Artifactory instance itself: an attacker who escalates access could tamper with artifacts consumed by every downstream build. Because Wiz’s research and the shared KEV addition date tie CVE-2026-42016 to its sibling CVE-2026-42018 (an authentication flaw in the same product), organizations running any pre-7.133.11 Artifactory Self-Hosted instance should treat this as one combined upgrade, not two separate patch decisions.

Frequently Asked Questions

What is CVE-2026-42016? A CVSS 8.1 incorrect-authorization vulnerability in JFrog Artifactory Self-Hosted (before 7.133.11) that lets an attacker escalate privileges because token scope isn’t validated, only signature and issuer.

Is CVE-2026-42016 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026, and Wiz has published research describing in-the-wild exploitation.

Is this related to CVE-2026-42018? Yes — both affect JFrog Artifactory, were added to CISA KEV the same day, and are referenced together in Wiz’s exploitation research.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools