CVE-2026-42016
HIGH · 8.1 KEV EPSS 0.9%KEV-listed; Wiz reports in-the-wild exploitation with C2 staging; CISA alert issued.
What: JFrog Artifactory Self Hosted (before v7.133.11) privilege escalation via improper token scope validation; CVSS 8.1 HIGH.
Why it matters: KEV-listed as of 2026-09-11 with confirmed active exploitation. Wiz Research documented in-the-wild chaining of CVE-2026-42016 with CVE-2026-42018 to achieve auth bypass, privilege escalation, and C2 backdoor deployment on self-hosted instances. CISA issued alert. Urgent patching required.
Where it's seen: CISA KEV alert, Wiz threat intel, Bleeping Computer coverage, security researcher posts describing live attack chains and Rust backdoor payloads. High engagement across Bluesky and threat feeds.
RISK: CRITICAL — Active exploitation chained with auth bypass; backdoor deployment; KEV-listed.
Description
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None