JFrog Artifactory Self-Managed bug can bypass access checks
JFrog Artifactory Self-Managed has a CERT-Bund advisory for 25 vulnerabilities in versions Self-Managed <7.161.16. An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in Self-Managed 7.161.16Fix recorded today
- Affected versions
- Self-Managed <7.161.16
- Affects
- JFrog Artifactory Self-Managed+2 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data.
What to do
Check your JFrog Artifactory Self-Managed version. If it is Self-Managed <7.161.16, this advisory applies.
Update JFrog Artifactory Self-Managed to Self-Managed 7.161.16 or newer.
Technical details
Affected software: JFrog Artifactory Self-Managed, Sonstiges, UNIX
An attacker can exploit multiple vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, impersonate users, disclose sensitive information, or manipulate protected data. The advisory tracks CVE-2026-42018, CVE-2026-65926, CVE-2026-66016, CVE-2026-66375, CVE-2026-66376, CVE-2026-66377, CVE-2026-66378, CVE-2026-66379. In CERT-Bund's CSAF data, affected versions are Self-Managed <7.161.16, and the fixed version is Self-Managed 7.161.16. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX.
References
- wid.cert-bund.de · wid-sec-w-2026-2808.json technical description
- github.com · GHSA-3q94-gprh-7pwm third party advisory
- github.com · GHSA-4hqf-vjqg-r5mp third party advisory
- github.com · GHSA-4m9c-v4gj-j8h4 third party advisory
- github.com · GHSA-592j-rr27-g7v3 third party advisory
- github.com · GHSA-5hcg-vq85-36gr third party advisory
- github.com · GHSA-658v-qxp8-f8jg third party advisory
- github.com · GHSA-6f7v-qw6v-g527 third party advisory
- github.com · GHSA-8p4r-xhj4-hcxq third party advisory
- github.com · GHSA-8qxj-ppp3-wj5q third party advisory
- github.com · GHSA-972j-37fp-4fxj third party advisory
- github.com · GHSA-9pg7-45vf-fg47 third party advisory
- github.com · GHSA-c4qm-8pgx-8w9v third party advisory
- github.com · GHSA-fwvx-mgc3-hfxw third party advisory
- github.com · GHSA-g2mp-x73p-93xc third party advisory
- github.com · GHSA-g827-5jxh-c39h third party advisory
- github.com · GHSA-gx5w-3352-3hcw third party advisory
- github.com · GHSA-h9p5-mfwv-xgr3 third party advisory
- github.com · GHSA-j8f7-jqv8-r34p third party advisory
- github.com · GHSA-jh2f-hwv7-p5g3 third party advisory
- github.com · GHSA-p589-cm2m-mwpc third party advisory
- github.com · GHSA-p5w8-5mcx-xjqc third party advisory
- github.com · GHSA-pfc3-2f49-5cw6 third party advisory
- github.com · GHSA-pqw8-h4c8-xg3j third party advisory
- github.com · GHSA-rm3v-36x6-mr48 third party advisory
- github.com · GHSA-v7m3-mxh9-fx63 third party advisory
- cisa.gov · known-exploited-vulnerabilities-catalog third party advisory
- wiz.io · artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 third party advisory