ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1

CVE-2026-42016 · JFrog Artifactory Incorrect Authorization Vulnerability

Identyfikator
CVE-2026-42016
CVSS
8.1 HIGH
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
JFrog
Produkt
Artifactory
Dodano do KEV
2026-09-11
Termin CISA
2026-09-25
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.