SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65616

HIGH · CVSS 8.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

A vulnerability exists due to improper authorization validation in the refresh token signature, enabling non-admin users to acquire a signed JFrog administrator token. This could lead to unauthorized access and potential compromise of sensitive administrative functions. Organizations using JFrog products should prioritize remediation to mitigate the risk of privilege escalation and data breaches.

CVE
CVE-2026-65616
Severity
HIGH
CVSS
8.8
EPSS
0.22%

Original NVD Description

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

Related CVEs

Other vulnerabilities affecting the same vendor(s)