JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
References
| Link | Resource |
|---|---|
| https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases | Release Notes |
| https://docs.jfrog.com/releases/docs/jfrog-security-advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018 | US Government Resource |
| https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-12 18:17
Updated : 2026-09-12 04:16
NVD link : CVE-2026-42018
Mitre link : CVE-2026-42018
CVE.ORG link : CVE-2026-42018
JSON object : View
Products Affected
jfrog
- artifactory
CWE
CWE-287
Improper Authentication
