Privilege Escalation Vulnerability in JFrog Artifactory by JFrog
CVE-2026-42016
Key Information:
- Vendor
Jfrog
- Status
- Vendor
- CVE Published:
- 27 July 2026
Badges
What is CVE-2026-42016?
Certain versions of JFrog Artifactory (Self Hosted) are at risk of a privilege escalation vulnerability due to inadequate validation of token signatures and issuers. This weakness allows an attacker to exploit improper token validation, potentially leading to unauthorized access and elevated privileges within the system. It is essential for users to update to version 7.133.11 or later to mitigate this security risk effectively.
CISA has reported CVE-2026-42016
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-42016 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
artifactory 0 < 7.133.11
News Articles
More JFrog Artifactory bugs under attack, and all 3 have patches
If you're waiting for a sign to upgrade to a fixed version: this is it
10 hours ago
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.
11 hours ago
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Attackers chained two JFrog Artifactory flaws on unupdated servers to gain admin control, while a third flaw was exploited separately.
20 hours ago
References
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
