Back

HIGH KEV

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

Published Jul 27, 2026 ·Due Sep 25, 2026

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner JFROG
Published Jul 27, 2026
Updated Sep 12, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Sep 11, 2026
NVD
Status Analyzed
Modified Sep 12, 2026
Red Hat
Severity n/a
Public date n/a