JFrog Artifactory Incorrect Authorization Vulnerability

cve CVE-2026-42016 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
JFrog Artifactory Incorrect Authorization Vulnerability JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are una… the claim
Severity
HIGH NVD
CVSS
8.8 NVD
Exploited
yes CISA Known Exploited Vulnerabilities
Known ransomware campaign use
Unknown CISA Known Exploited Vulnerabilities
Due date
2026-09-25 CISA Known Exploited Vulnerabilities
Fixed in
7.133.11 NVD
Vendor
JFrog CISA Known Exploited Vulnerabilities
jfrog NVD
Product
Artifactory CISA Known Exploited Vulnerabilities
artifactory NVD
CWE
CWE-863 CISA Known Exploited Vulnerabilities
CWE-863 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild · CISA Known Exploited Vulnerabilities 2026-09-11
  6. Used in ransomware campaigns

Timeline

2026-07-27first spoke of it: JFrog Artifactory Incorrect Authorization VulnerabilityNVD
2026-09-11first spoke of it: JFrog Artifactory Incorrect Authorization VulnerabilityCISA Known Exploited Vulnerabilities
2026-09-25Due dateCISA Known Exploited Vulnerabilities

What it is to other things

affectsjfrog/artifactory
NVD
made_byjfrog
NVD
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD8.8
receipt
Source
NVD
Its words
8.8
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC8.8
2026-09-29 09:45 UTC8.1
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
CISA Known Exploited VulnerabilitiesCWE-863
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-863
Read by
field:cwes
Said since
2026-10-06 12:19 UTC
Last answered
2026-10-06 17:36 UTC
2026-10-06 12:19 UTCCWE-863
2026-09-28 11:44 UTC—
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
CWE
cwe
NVDCWE-863
receipt
Source
NVD
Its words
CWE-863
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-863
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWES
cwes
CISA Known Exploited VulnerabilitiesCWE-863
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-863
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-09-25
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-09-25
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Exploitation
exploitation
NVDactive
Reliable evidence that it is exploited in the wild.
receipt
Source
NVD
Its words
active
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCactive
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Fixed in
fixed_in
NVD7.133.11
receipt
Source
NVD
Its words
7.133.11
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC7.133.11
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Product
product
different words
CISA Known Exploited VulnerabilitiesArtifactory
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Artifactory
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Product
product
different words
NVDartifactory
receipt
Source
NVD
Its words
artifactory
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCartifactory
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
different words
CISA Known Exploited VulnerabilitiesJFrog
receipt
Source
CISA Known Exploited Vulnerabilities
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2026-42016",
  "cwes": "CWE-863",
  "dateAdded": "2026-09-11",
  "dueDate": "2026-09-25",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",
  "product": "Artifactory",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
  "vendorProject": "JFrog",
  "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability"
}
—
Vendor
vendor
different words
NVDjfrog
receipt
Source
NVD
Its words
jfrog
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCjfrog
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "artifactory",
            "vendor": "jfrog",
            "versions": [
              {
                "lessThan": "7.133.11",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "reefs@jfrog.com"
      }
    ],
    "cisaActionDue": "2026-09-25",
    "cisaExploitAdd": "2026-09-11",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
                "matchCriteriaId": "817DC3BE-A8A2-42D7-9407-2BA24639E9A0",
                "versionEndExcluding": "7.133.11",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope."
      }
    ],
    "id": "CVE-2026-42016",
    "lastModified": "2026-09-12T04:16:32.483",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "reefs@jfrog.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42016",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-11T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-27T20:16:39.613",
    "references": [
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases"
      },
      {
        "source": "reefs@jfrog.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
      }
    ],
    "sourceIdentifier": "reefs@jfrog.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "reefs@jfrog.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

JFrog Artifactory Incorrect Authorization Vulnerability
zetlyn/cve-kev · 2026-09-11
cwe CWE-863 cwes CWE-863 due_date 2026-09-25 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Artifactory vendor JFrog
JFrog Artifactory Incorrect Authorization Vulnerability
zetlyn/cve-nvd · 2026-07-27
automatable no cvss 8.8 cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cwe CWE-863 exploitation active fixed_in 7.133.11 product artifactory severity HIGH status Analyzed technical_impact total vendor jfrog source