CVE-2026-42018

Summary

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Affected Software

VendorProductVersion RangeStatus
jfrogartifactory0 < 7.146.8affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

References