CVE-2026-42018
EUVD-2026-5738812.08.2026, 18:17
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jfrog | artifactory | 𝑥 < 7.146.8 | CNA |
Common Weakness Enumeration