CVE-2026-42018
Aug 12, 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources....
Read Advisory
2 advisories affecting Jfrog Artifactory
2
Total CVEs
0
Critical
2
High
Aug 12, 2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources....
Jul 27, 2026
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope....