CVE-2026-42018: Anonymous user token generation exposure in JFrog Artifactory
Published Aug 12, 2026
·Updated
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Affected Software
1 affected component
JFrog Artifactory
Event History
Aug 12, 2026
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42018?
CVE-2026-42018 has a high severity rating of 7.5.
2
How do I fix CVE-2026-42018?
To fix CVE-2026-42018, ensure that anonymous access is properly configured and do not allow unauthenticated users to generate internal tokens.
3
What is the risk of CVE-2026-42018?
CVE-2026-42018 carries a risk score of 43.
4
What systems are affected by CVE-2026-42018?
CVE-2026-42018 affects JFrog Artifactory installations.
5
Is anonymous user token generation exposed in CVE-2026-42018?
Yes, CVE-2026-42018 exposes internal anonymous-user token generation to unauthenticated calls when anonymous access is disabled.