AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-42018

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

JFrog Artifactory is vulnerable to a flaw that allows an unauthenticated user to receive an internal anonymous-user token, even when anonymous access is disabled. This could lead to unauthorized access to sensitive resources, posing a significant risk to organizations utilizing this software. Organizations using JFrog Artifactory should prioritize addressing this vulnerability to protect their sensitive data from potential exploitation.

CVE
CVE-2026-42018
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.