GPU VulnDB

Database/Control plane, storage & DevOps

JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged token

CVSS 8.8CVE-2026-42016Control plane, storage & DevOpsKnown exploitedcurated

Impact

Artifactory validated the signature and issuer of an access token but not its scope, so a holder of any low-privileged token can act with privileges it was never granted. In a GPU fleet, Artifactory is usually the registry that container images, CUDA base layers, driver packages and model artifacts are pulled from; write access there is a supply-chain foothold that lands on every node that pulls an image. This is being exploited in the wild and is in the KEV catalogue.

Who can reach it

Anyone holding a valid low-privileged Artifactory token - a build job token, a CI runner, a read-only service account - over the network. No admin credentials needed.

What to do

Upgrade self-hosted Artifactory to 7.133.11 or later and restart the service. Given confirmed in-the-wild exploitation, also audit for unexpected admin users, tokens and repository changes, rotate access tokens and any credentials stored in Artifactory, and verify the integrity of images and packages published during the exposure window.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.