Improper Verification of Cryptographic Signature in Artifactory - CVE-2026-65616
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to administrator privileges.
The vulnerability exists due to improper verification of cryptographic signature in refresh-token signature validation when processing refresh tokens. A remote user can submit a crafted refresh token to escalate privileges to administrator privileges.