← back
CVE-2026-42018highunder attackCWE-287

Anonymous user token generation exposure in JFrog Artifactory

71Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 11%
from disclosure to weapon33 days
Published on NVDAug 12
1st PoC+33d
CISA KEV+30d
exploitation probability
11%top 4% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2026-09-25

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

JFrog Artifactory incorrectly generates and reveals an internal anonymous-user token to unauthenticated users even when anonymous access is supposed to be disabled. This token can be misused to access sensitive resources that should be protected.

Technical detail

When anonymous access is disabled, JFrog Artifactory fails to properly enforce authentication checks and returns an internal anonymous-user token to unauthenticated callers (CWE-287: Improper Authentication). An attacker can obtain this token and use it to access protected resources, bypassing intended access controls. The vulnerability affects availability and confidentiality of restricted artifacts.

Summary generated and translated by AI from the official description.
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
jfrog · artifactory
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.