THREATOPS
THREAT OPSCVEs › CVE-2026-42018

CVE-2026-42018 — JFrog Artifactory Improper Authentication Vulnerability

CISA KEVExploited: confirmedJFrog

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Vulnerability details

Related reporting