CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

  • Published Aug 12, 2026
  • CVSS 7.5 high
  • 9.8% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2026-42018 at the National Vulnerability Database