CVE-2026-42018

Executive Summary

CVE-2026-42018: JFrog Artifactory may return an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, enabling attackers to access sensitive resources. The vulnerability is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2026-08-12T18:17:29.473 - Last Modified: 2026-09-12T04:16:33.587

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-09-11)

Original Description: JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

"Do, or do not. There is no try."

— Yoda
Source: NVD