Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1
CVE-2026-42016 · JFrog Artifactory Incorrect Authorization Vulnerability
- Identyfikator
- CVE-2026-42016
- CVSS
- 8.1 HIGH
- CISA KEV
- AKTYWNIE WYKORZYSTYWANE
- Producent
- JFrog
- Produkt
- Artifactory
- Dodano do KEV
- 2026-09-11
- Termin CISA
- 2026-09-25
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.