CVE-2026-42016: JFrog Artifactory
JFrog Artifactoryには、トークンシグネチャ/発行者の検証チェックとトークンのスコープではなく、特権エスカレーション攻撃につながる誤った認可脆弱性が含まれています。
CISA (English)
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- ベンダー
- JFrog
- 製品
- Artifactory
- 脆弱性
- JFrog Artifactory Incorrect Authorization Vulnerability
- 追加日
- 2026/09/11
- CISA対応期限(米国連邦機関向け)
- 2026/09/25
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-863
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02