{"data":{"id":"b8c7598c-80f2-4fc8-9da2-bab5123370a7","title":"CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability","summary":"JFrog Artifactory has a security flaw that allows attackers to gain elevated privileges by bypassing authorization checks. The vulnerability happens because the software validates the token's signature and issuer (who created it), but fails to check the token's scope (what permissions it allows), letting attackers use tokens beyond their intended access level.","solution":"Apply mitigations according to vendor instructions. Consult JFrog's security advisories at https://docs.jfrog.com/releases/docs/jfrog-security-advisories and Artifactory release notes at https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases. Follow CISA's BOD 26-04 guidance for patching timelines. If mitigations are unavailable for cloud services, discontinue use of the product.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42016","publishedAt":"2026-09-11T00:00:00.000Z","cveId":"CVE-2026-42016","cweIds":["CWE-863"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["JFrog Artifactory"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"active","epssScore":0.00266,"patchAvailable":true,"disclosureDate":"2026-09-11T00:00:00.000Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.72,"researchCategory":null,"atlasIds":["AML.T0010"]}}