Improper Authentication in JFrog Artifactory - CVE-2026-42018
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper authentication in anonymous-user token generation when handling unauthenticated requests while anonymous access is disabled. A remote attacker can request a token and receive an internal anonymous-user token to disclose sensitive information.
Exploitation is possible even when anonymous access is disabled.