CVE-2026-42018
EUVD-2026-5738812.08.2026, 18:17
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jfrog | artifactory | 𝑥 < 7.111.20 |
| jfrog | artifactory | 7.117.0 ≤ 𝑥 < 7.117.27 |
| jfrog | artifactory | 7.125.0 ≤ 𝑥 < 7.125.19 |
| jfrog | artifactory | 7.133.0 ≤ 𝑥 < 7.133.28 |
| jfrog | artifactory | 7.146.0 ≤ 𝑥 < 7.146.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References