CVE-2026-42018
Executive Summary
CVE-2026-42018: JFrog Artifactory may return an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, enabling attackers to access sensitive resources. The vulnerability is actively exploited in the wild (CISA KEV).
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2026-08-12T18:17:29.473 - Last Modified: 2026-09-12T04:16:33.587
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-09-11)
Original Description: JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
"Do, or do not. There is no try."
— Yoda
Source: NVD