๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability
Summary
JFrog Artifactory has a security flaw that allows attackers to gain elevated privileges by bypassing authorization checks. The vulnerability happens because the software validates the token's signature and issuer (who created it), but fails to check the token's scope (what permissions it allows), letting attackers use tokens beyond their intended access level.
Solution / Mitigation
Apply mitigations according to vendor instructions. Consult JFrog's security advisories at https://docs.jfrog.com/releases/docs/jfrog-security-advisories and Artifactory release notes at https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases. Follow CISA's BOD 26-04 guidance for patching timelines. If mitigations are unavailable for cloud services, discontinue use of the product.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
September 10, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42016
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 72%