CVE-2026-42018

Summary

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Affected Software

VendorProductVersion RangeStatus
jfrogartifactory0 < 7.111.20affected
jfrogartifactory7.117.0 < 7.117.27affected
jfrogartifactory7.125.0 < 7.125.19affected
jfrogartifactory7.133.0 < 7.133.28affected
jfrogartifactory7.146.0 < 7.146.8affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: partial

Additional References

References