JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass
CVE-2026-42018
Early Release
Description
JFrog Artifactory contains an information disclosure caused by returning an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, letting unauthenticated attackers access sensitive resources. The exploit requires anonymous access to be disabled.
Severity
High
CVSS Score
7.5
Exploit Probability
10%
Published Date
September 18, 2026
Template Author
theamanrawat
CVE-2026-42018.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-42018
CWE ID:
cwe-287
References
https://docs.jfrog.com/releases/docs/jfrog-security-advisorieshttps://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201https://github.com/BL0odz/JFrog_CVE-2026-65615-ByGLMhttps://edrabb.fr/posts/full-chain-preauth-rce-jfrog-artifactory/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
Remediation Steps
Update to the latest version where this issue is fixed.