Jfrog Artifactory Vulnerabilities

2 advisories affecting Jfrog Artifactory

2

Total CVEs

0

Critical

2

High

CVE-2026-42018

Aug 12, 2026

High 7.5

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources....

Read Advisory

CVE-2026-42016

Jul 27, 2026

High 8.8

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope....

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.