CVE-2026-42018 · CVSS 7.5 HIGH · KEV 2026-09-11 · patch available
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Is CVE-2026-42018 exploited?
Listed in the CISA KEV catalog on 2026-09-11.
Federal remediation due 2026-09-25.
Public exploit code: none found in monitored sources.