Authorization Vulnerability in JFrog Products Exposing Admin Tokens
CVE-2026-65616
8.8HIGH
What is CVE-2026-65616?
An authorization flaw exists in JFrog products, where improper validation of refresh token signatures allows non-admin users to acquire a signed administrator token. This vulnerability could lead to unauthorized access and can potentially compromise the integrity of sensitive operations within the JFrog environment.
Affected Version(s)
artifactory 0 < 7.146.27
