[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-42016":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-12T01:55:19.833Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":24,"related":25,"reserved_at":9,"published_at":26,"modified_at":27,"state":28,"summary":29,"references_raw":40,"kevs":63,"epss":74,"epss_history":76,"metrics":213,"affected":224},"CVE-2026-42016","JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-863","Incorrect Authorization","The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.","weakness","Incomplete","Class","High",[],[],[],[],[],[],[],"2026-07-27T19:20:56.352Z","2026-09-11T19:58:23.708Z","Analyzed",{"cisa_kev":30,"cisa_ransomware":31,"cisa_vendor":32,"epss_severity":33,"epss_score":34,"severity":35,"severity_score":36,"severity_version":37,"severity_source":38,"severity_vector":39,"severity_status":28},true,false,"JFrog","low",0.00266,"high",8.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[41,47,52,57],{"url":42,"sources":43,"tags":45},"https://docs.jfrog.com/releases/docs/jfrog-security-advisories",[44,38],"cve.org",[46],"Vendor Advisory",{"url":48,"sources":49,"tags":50},"https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",[44,38],[46,51],"Release Notes",{"url":53,"sources":54,"tags":55},"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201",[44,38],[56],"Third Party Advisory",{"url":58,"sources":59,"tags":60},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016",[44,38],[61,62],"Government Resource","US Government Resource",[64],{"source":65,"vendor":32,"product":66,"date_added":67,"vulnerability_name":68,"short_description":69,"required_action":70,"due_date":71,"known_ransomware_campaign_use":72,"notes":73,"exploitation_type":9},"cisa","Artifactory","2026-09-11","JFrog Artifactory Incorrect Authorization Vulnerability","JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.","Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","2026-09-25","Unknown","https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-42016",{"date":67,"score":34,"percentile":75},0.184,[77,81,84,87,91,94,97,100,103,106,109,112,115,118,121,124,127,130,133,136,139,142,145,148,151,154,157,160,164,166,169,172,175,178,181,184,187,190,192,195,198,201,203,206,209,212],{"date":78,"score":79,"percentile":80},"2026-07-28",0.00209,0.11201,{"date":82,"score":79,"percentile":83},"2026-07-29",0.11182,{"date":85,"score":79,"percentile":86},"2026-07-30",0.11179,{"date":88,"score":89,"percentile":90},"2026-07-31",0.0023,0.13914,{"date":92,"score":89,"percentile":93},"2026-08-01",0.13903,{"date":95,"score":89,"percentile":96},"2026-08-02",0.13902,{"date":98,"score":89,"percentile":99},"2026-08-03",0.13909,{"date":101,"score":89,"percentile":102},"2026-08-04",0.13864,{"date":104,"score":89,"percentile":105},"2026-08-05",0.13809,{"date":107,"score":89,"percentile":108},"2026-08-06",0.13802,{"date":110,"score":89,"percentile":111},"2026-08-07",0.13784,{"date":113,"score":89,"percentile":114},"2026-08-08",0.13775,{"date":116,"score":89,"percentile":117},"2026-08-09",0.13754,{"date":119,"score":89,"percentile":120},"2026-08-10",0.13763,{"date":122,"score":89,"percentile":123},"2026-08-11",0.13847,{"date":125,"score":89,"percentile":126},"2026-08-12",0.13872,{"date":128,"score":89,"percentile":129},"2026-08-13",0.13875,{"date":131,"score":89,"percentile":132},"2026-08-14",0.13879,{"date":134,"score":89,"percentile":135},"2026-08-15",0.14036,{"date":137,"score":89,"percentile":138},"2026-08-16",0.14059,{"date":140,"score":89,"percentile":141},"2026-08-17",0.13985,{"date":143,"score":89,"percentile":144},"2026-08-18",0.13991,{"date":146,"score":89,"percentile":147},"2026-08-19",0.14033,{"date":149,"score":89,"percentile":150},"2026-08-20",0.14045,{"date":152,"score":89,"percentile":153},"2026-08-21",0.14048,{"date":155,"score":89,"percentile":156},"2026-08-22",0.14047,{"date":158,"score":89,"percentile":159},"2026-08-23",0.14054,{"date":161,"score":162,"percentile":163},"2026-08-24",0.00234,0.14125,{"date":165,"score":162,"percentile":163},"2026-08-25",{"date":167,"score":162,"percentile":168},"2026-08-26",0.14173,{"date":170,"score":162,"percentile":171},"2026-08-27",0.14158,{"date":173,"score":162,"percentile":174},"2026-08-28",0.14186,{"date":176,"score":162,"percentile":177},"2026-08-29",0.1419,{"date":179,"score":162,"percentile":180},"2026-08-30",0.142,{"date":182,"score":162,"percentile":183},"2026-08-31",0.14194,{"date":185,"score":162,"percentile":186},"2026-09-01",0.14208,{"date":188,"score":162,"percentile":189},"2026-09-02",0.14211,{"date":191,"score":162,"percentile":189},"2026-09-03",{"date":193,"score":34,"percentile":194},"2026-09-04",0.1822,{"date":196,"score":34,"percentile":197},"2026-09-05",0.18264,{"date":199,"score":34,"percentile":200},"2026-09-06",0.18278,{"date":202,"score":34,"percentile":200},"2026-09-07",{"date":204,"score":34,"percentile":205},"2026-09-08",0.18288,{"date":207,"score":34,"percentile":208},"2026-09-09",0.18393,{"date":210,"score":34,"percentile":211},"2026-09-10",0.18392,{"date":67,"score":34,"percentile":75},[214,221],{"source":44,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":215,"cvss_v4_0":9},{"baseScore":216,"baseSeverity":217,"vectorString":218,"impactScore":219,"exploitabilityScore":220},8.1,"HIGH","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",8.7,7.2,{"source":38,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":222,"cvss_v4_0":9},{"baseScore":36,"baseSeverity":217,"vectorString":39,"impactScore":223,"exploitabilityScore":220},9.8,[225],{"ecosystem":9,"name":226,"vendor":227,"product":226,"cpe_part":228,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":229},"artifactory","jfrog","a",[230],{"version":231,"is_range":30,"range_type":232,"version_start":9,"version_start_type":9,"version_end":233,"version_end_type":234,"fixed_in":9},"\u003C 7.133.11","cpe","7.133.11","excluding"]