HIGH
CVE-2026-42018
CVSS
7.5
KEV
Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
0.92%
Probability of exploitation in next 30 days
58.7th percentile
References
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
Release Notes
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
US Government Resource
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.