VDB

GCVE-110-NCSC-2026-272

GCVE-110-NCSC-2026-272
Advisory PublishedCVSS 8.1/10
Vulnetix · Advisory published July 31, 2026
JFrog Artifactory (Self Hosted) versions prior to 7.133.11 are susceptible to privilege escalation due to improper validation of token scope despite verifying token signature and issuer.

Weaknesses (CWE)

CWE-863Incorrect AuthorizationCWE-347Improper Verification of Cryptographic SignatureCWE-502Deserialization of Untrusted DataCWE-918Server-Side Request Forgery (SSRF)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-862Missing Authorization

Risk Scores

CVSS 3.1
8.1/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
JFrogvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,425 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›