Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Published: 2026-08-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows JFrog Artifactory to return an internal anonymous‑user token to an unauthenticated caller when anonymous access is disabled. This token can be used to read sensitive artifacts or configuration data. The exposed token effectively bypasses authentication controls, giving the caller privileges it should not possess. The weakness is identified as CWE‑287.

Affected Systems

The flaw applies to deployments of JFrog Artifactory where anonymous access is disabled. No specific version is provided, so all releases that expose the token behavior are potentially affected. Administrators should review versions in use and check configuration files noting that the issue occurs even with anonymous access turned off.

Risk and Exploitability

The CVSS score of 7.5 indicates a significant threat. There is no available EPSS or KEV listing, suggesting current exploitation activity is unknown, but the flaw remains exploitable from the network as any unauthenticated client can retrieve the token. Attackers could leverage the token to read or download confidential repositories, making this a critical concern for organizations relying on Artifactory for secure storage.

Generated by OpenCVE AI on August 12, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest JFrog Artifactory patch or upgrade to a version where the token exposure is fixed.
  • Verify that the configuration does not expose the internal anonymous‑user token by testing API responses, and, if necessary, restrict or remove the endpoint that returns the token.
  • Block or limit network access to the Artifactory API endpoints that could reveal the token through firewall rules or network segmentation until the vendor releases a fix.

Generated by OpenCVE AI on August 12, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Title Anonymous user token generation exposure in JFrog Artifactory
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-08-18T18:14:10.646Z

Reserved: 2026-04-23T13:41:13.755Z

Link: CVE-2026-42018

cve-icon Vulnrichment

Updated: 2026-08-13T15:05:13.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T18:17:29.473

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-42018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:30:10Z

Weaknesses