HIGHVulnerability
Verified
Global

CISA KEV: JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Analysis

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-11. Remediation due: 2026-09-25.

Indicators of Compromise (1)

CVE (1)
CVE-2026-42018
Source Attribution

Originally published by CISA KEV on Sep 11, 2026. Verified by: CISA.

Related Threats