Executive brief
JFrog Artifactory is a software repository manager used by organizations to store and manage build artifacts and dependencies. An authorization flaw allows authenticated users to escalate their privileges to higher levels than intended, potentially gaining access to sensitive repositories, artifacts, or administrative functions they should not be able to control.
Technical details
JFrog Artifactory contains an incorrect authorization vulnerability where the token validation logic checks the signature and issuer but fails to properly validate the token's scope constraints. This allows an authenticated attacker with a valid token to perform actions and access resources beyond the scope granted by their token. The vulnerability is exploitable by any user with a valid token, without requiring administrative credentials. An attacker can leverage this to escalate privileges, access restricted artifacts, modify repositories, or perform other privileged operations. The vulnerability has been observed actively exploited in the wild.
Affected products
- JFrog Artifactory
Timeline
- 2026-09-11: disclosed
- 2026-09-11: exploited: Actively exploited in the wild