CVE-2026-42018
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
12/08/2026
Last modified:
18/08/2026
Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



