CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0272 [1.00] [M/H] Vulnerabilities patched in JFrog Artifactory

unknownCVE-2026-42016CVE-2026-42017CVE-2026-65616CVE-2026-65617CVE-2026-65618CVE-2026-65921
JFrog has patched multiple vulnerabilities in JFrog Artifactory. The vulnerabilities concern various components of JFrog Artifactory. - There is a possibility of privilege escalation because the system does not check the scope of tokens, allowing an attacker to elevate their rights. - Additionally, users with limited rights can gain access to privileged authorization materials and can obtain an administrator token through weak refresh token validation. - Further, there is a deserialization issue in the package handling that can lead to unauthorized code execution or data manipulation. - Improper URL validation makes it possible to make unauthorized requests and access internal services or cached data. - A path traversal vulnerability can lead to writing files outside the intended directory. - There is also an authorization weakness in metadata handling, allowing users with limited rights to modify metadata. - Specific components such as the Ansible repository, Terraform remote repositories, and Cargo remote repository are vulnerable to Server-Side Request Forgery (SSRF) attacks, where undesired HTTP requests can be executed and their responses viewed. - Further, there is a vulnerability in the internal authentication system that enables privilege escalation. - Finally, users with read rights on a repository can also view environment variables of other repositories, which can lead to exposure of confidential build secrets. OpenAI mentioned in a public blog post that the vulnerabilities described above were exploited as ZeroDay vulnerabilities by an OpenAI model to independently gain access to the internet and thereby be able to attack a third party. OpenAI immediately notified JFrog so that JFrog could patch the vulnerabilities as quickly as possible.

CSIRTS triage

What
Multiple vulnerabilities including token scope bypass allowing privilege escalation, weak refresh token validation exposing admin tokens, deserialization flaws enabling code execution, improper URL validation allowing unauthorized service access, path traversal enabling writes outside intended directories, and authorization weaknesses in metadata handling.
Who is affected
All deployments of JFrog Artifactory with standard configurations are affected.
Urgency
High; multiple critical flaws including RCE and privilege escalation require immediate patching.
Action
Apply JFrog Artifactory security patches immediately as released by vendor.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Artifactory

Get an email when a new Artifactory advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-31
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0272

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-42016coverage & exploitation statusNVD · CVE.org
CVE-2026-42017coverage & exploitation statusNVD · CVE.org
CVE-2026-65616coverage & exploitation statusNVD · CVE.org
CVE-2026-65617coverage & exploitation statusNVD · CVE.org
CVE-2026-65618coverage & exploitation statusNVD · CVE.org
CVE-2026-65921coverage & exploitation statusNVD · CVE.org
CVE-2026-65922coverage & exploitation statusNVD · CVE.org
CVE-2026-65923coverage & exploitation statusNVD · CVE.org
CVE-2026-65924coverage & exploitation statusNVD · CVE.org
CVE-2026-65925coverage & exploitation statusNVD · CVE.org
CVE-2026-66014coverage & exploitation statusNVD · CVE.org
CVE-2026-66015coverage & exploitation statusNVD · CVE.org
CVE-2026-66018coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for JFrog Artifactory

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories