AllCyberNews

CVE-2026-42018

Anonymous user token generation exposure in JFrog Artifactory

CVSS 7.5 high · jfrog artifactory · published 2026-08-12

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Coverage 1 source

  1. 2026-09-11 CISA Cybersecurity Advisories critical CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA added three exploited vulnerabilities to its KEV Catalog: CVE-2026-42016, CVE-2026-42018, and CVE-2026-84869.

Mentioned with

CVE-2026-42016 CVE-2026-84869

Also covered