CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-09-11. EPSS: 9.8% chance of exploitation in the next 30 days.
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Affected products
- JFrog Artifactory: before 7.111.20 (fixed in 7.111.20); from 7.117.0, before 7.117.27 (fixed in 7.117.27); from 7.125.0, before 7.125.19 (fixed in 7.125.19); from 7.133.0, before 7.133.28 (fixed in 7.133.28); from 7.146.0, before 7.146.8 (fixed in 7.146.8)
Published 2026-08-12. Last modified 2026-10-01.