CVE-2026-42018
HIGHJFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Published: 8/12/2026Modified: 10/1/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (4)
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releasesRelease Noteshttps://docs.jfrog.com/releases/docs/jfrog-security-advisoriesVendor Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018US Government Resourcehttps://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201Third Party Advisory