Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Published: 2026-08-12
Score: 7.5 High
EPSS: 11.0% Moderate
KEV: Yes
Impact: Unauthenticated token abuse leading to unauthorized access to sensitive resources
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows JFrog Artifactory to return an internal anonymous‑user token to an unauthenticated caller even when anonymous access is disabled. This token can be used to read sensitive artifacts or configuration data. The exposed token effectively bypasses authentication controls, giving the caller privileges it should not possess. The weakness is identified as CWE‑287.

Affected Systems

The flaw applies to deployments of JFrog Artifactory where anonymous access is disabled. No specific version is provided, so all releases that expose the token behavior are potentially affected. Administrators should review versions in use and check configuration files noting that the issue off.

Risk and Exploitability

The CVSS score of 7.5 indicates a significant threat. The EPSS score is 11% and the vulnerability is listed in CISA KEV, indicating that it is likely to be exploited from the network as any unauthenticated client can retrieve the token. Attackers could leverage the token to read or download confidential repositories, making this a critical concern for organizations relying on Artifactory for secure storage.

Generated by OpenCVE AI on September 21, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest JFrog Artifactory patch that resolves the token exposure issue, or upgrade to a version that fixes the behavior.
  • Modify the Artifactory configuration to disable or remove the endpoint that returns anonymous tokens when anonymous access is disabled.
  • Restrict network access to Artifactory API endpoints via firewall rules or network segmentation to limit exposure until a patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
References
Metrics kev

{'dateAdded': '2026-09-11T00:00:00+00:00', 'dueDate': '2026-09-25T00:00:00+00:00'}


Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Title Anonymous user token generation exposure in JFrog Artifactory
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-09-12T03:55:21.730Z

Reserved: 2026-04-23T13:41:13.755Z

Link: CVE-2026-42018

cve-icon Vulnrichment

Updated: 2026-08-13T15:05:13.966Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:29.473

Modified: 2026-09-12T04:16:33.587

Link: CVE-2026-42018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:45:10Z

Weaknesses