Database/Control plane, storage & DevOps
JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged token
Impact
Artifactory validated the signature and issuer of an access token but not its scope, so a holder of any low-privileged token can act with privileges it was never granted. In a GPU fleet, Artifactory is usually the registry that container images, CUDA base layers, driver packages and model artifacts are pulled from; write access there is a supply-chain foothold that lands on every node that pulls an image. This is being exploited in the wild and is in the KEV catalogue.
Who can reach it
Anyone holding a valid low-privileged Artifactory token - a build job token, a CI runner, a read-only service account - over the network. No admin credentials needed.
What to do
Upgrade self-hosted Artifactory to 7.133.11 or later and restart the service. Given confirmed in-the-wild exploitation, also audit for unexpected admin users, tokens and repository changes, rotate access tokens and any credentials stored in Artifactory, and verify the integrity of images and packages published during the exposure window.
References
Related entries
- VMware Avi Load Balancer: remote code execution on the Avi Controller control planeCVE-2026-47867 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: authenticated user can inject and execute code on the ControllerCVE-2026-47869 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: authenticated privilege escalation leading to remote code executionCVE-2026-47870 · VMware Avi Load Balancer (Controller control plane)High
- VMware Avi Load Balancer: directory traversal through weak file path validationCVE-2026-47871 · VMware Avi Load Balancer (Controller file path validation)High
- Apache CloudStack: metalink template registration gives a tenant root on the KVM hypervisor hostCVE-2026-50112 · Apache CloudStack (template registration via metalink and direct download to the KVM agent)High
- Jenkins: attacker-controlled config.xml deserialization allows user impersonation and code executionCVE-2026-53435 · Jenkins controller (config.xml deserialization of arbitrary core and plugin types)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.