CVE-2026-65616 is a privilege-escalation vulnerability in JFrog Artifactory affecting versions earlier than 7.146.27. The flaw is caused by incorrect authorization validation in refresh token signature handling. Due to this validation weakness, a non-administrative user can obtain a signed JFrog administrator token. The issue effectively breaks the intended trust boundary between lower-privileged users and administrator-level token issuance, enabling elevation from a regular authenticated account to administrative access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a deliberately vulnerable Docker training lab, not an exploit for a CVE. The container creates an unprivileged agente account and a root-owned protected file, then starts headless Chromium as root with --no-sandbox and an unauthenticated Chrome DevTools Protocol listener on 0.0.0.0:9222. The core exploit is run_cdp.py, a standalone Python script using urllib plus a manually implemented WebSocket client. It enumerates CDP pages via /json/list, connects to the selected page's dynamic WebSocket debugger endpoint, changes Chromium's download directory to /tmp/, triggers a data-URI download, then changes the download directory to /etc/sudoers.d/. JavaScript executed through Runtime.evaluate replaces the page anchor with a data URI containing a passwordless sudoers rule and clicks it. Because Chromium runs as root, the browser writes /etc/sudoers.d/agente, enabling unrestricted passwordless sudo for agente. The script verifies the injected policy and demonstrates elevated access with sudo touch. Supporting files build and run the Debian/Chromium container (Dockerfile, entrypoint.sh), generate the local download page (log.sh), and provide lifecycle/root-shell helpers (reinicio_full.sh, start.sh, root.sh).
This 18-file repository is a Docker-based, Spanish/English forensic recreation of an alleged JFrog Artifactory privilege-escalation chain, not an automated exploit framework. Its executable components are Dockerfile, docker-compose.yml, start.sh, and reset.sh; the remaining material is a phased Markdown operator guide. docker-compose deploys an isolated Alpine-based simulated agent, PostgreSQL 14, and JFrog Artifactory Pro 7.146.25. Artifactory alone has external-network access and exposes ports 8081 (API) and 8082 (UI) to the host. start.sh provisions anonymous access, PyPI/npm local/remote/virtual repositories, an agente-compartido user, readers-group read/write permissions, and a versioned reference token delivered through a Docker volume and rendered into plaintext client configuration files. The documented attack chain is: inspect plaintext pip/npm configuration to recover Basic-auth credentials; enumerate Artifactory repositories; upload an artifact to pypi-local as an unauthorized-by-role communication board; request a one-year refreshable token; alter only the JWT scope claim to applied-permissions/admin while retaining required internal claims; and submit the forged JWT with a valid refresh token and owner Basic authentication to the token endpoint. The claimed vulnerable refresh flow returns a new legitimate RS256-signed admin token, which is then used to create agente-admin. The repository importantly qualifies the claim: the full escalation was reportedly observed only where token/key material survived a downgrade from Artifactory 7.146.28/7.146.34 to 7.146.25; a clean 7.146.25 installation returns the original readers scope, so Phase 4 is not reliably reproduced by the default clean lab. Phase 6 describes, but does not implement, using an administrator-created remote repository as an SSRF/egress proxy and installing Groovy plugins for persistence.
This 22-file repository is a standalone, operational Python proof-of-exploitation package for a five-stage JFrog Artifactory pre-authentication RCE chain. Its primary entry point, attack-chain-package/exploit/exp.py, uses only the Python standard library and automates CVE-2026-42018 authentication bypass, refreshable-token issuance, CVE-2026-65616 JWT-claim forgery/administrator-token acquisition, system-import upload, and CVE-2026-65615-based Logback/Tomcat CGI command execution. forge_jwt.py is a separate helper for manually generating the forged JWT used in stage 3. The payload sample documents the resulting malicious ZIP and its Logback-based writes to web.xml, CGI scripts, and privileged Tomcat deployment descriptors. The repository also contains Docker/PostgreSQL deployment YAML, a baseline-validation record, two extensive Chinese technical reports, and shell recovery/verification scripts that remove the CGI backdoor and restore original Tomcat and Logback files. The exploit is destructive to the target web application because it replaces the normal Artifactory web.xml with a minimal CGI-only configuration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.