JFrog Artifactory Self-Managed bug can bypass access checks

Published September 11, 2026

JFrog Artifactory Self-Managed has a CERT-Bund advisory for 25 vulnerabilities in versions Self-Managed <7.161.16. An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in Self-Managed 7.161.16Fix recorded today
Affected versions
Self-Managed <7.161.16
Affects
JFrog Artifactory Self-Managed+2 more
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data.

What to do

Check your JFrog Artifactory Self-Managed version. If it is Self-Managed <7.161.16, this advisory applies.

Update JFrog Artifactory Self-Managed to Self-Managed 7.161.16 or newer.

Technical details

Affected software: JFrog Artifactory Self-Managed, Sonstiges, UNIX

An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data. The advisory tracks CVE-2026-42018, CVE-2026-65926, CVE-2026-66016, CVE-2026-66375, CVE-2026-66376, CVE-2026-66377, CVE-2026-66378, CVE-2026-66379. In CERT-Bund's CSAF data, affected versions are Self-Managed <7.161.16, and the fixed version is Self-Managed 7.161.16. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX.

References