/Vulnerability Library

JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass

CVE-2026-42018
Early Release

Description

JFrog Artifactory contains an information disclosure caused by returning an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, letting unauthenticated attackers access sensitive resources. The exploit requires anonymous access to be disabled.

Severity

High

CVSS Score

7.5

Exploit Probability

10%

Published Date

September 18, 2026

Template Author

theamanrawat

CVE-2026-42018.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-42018
CWE ID:
cwe-287

References

https://docs.jfrog.com/releases/docs/jfrog-security-advisorieshttps://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201https://github.com/BL0odz/JFrog_CVE-2026-65615-ByGLMhttps://edrabb.fr/posts/full-chain-preauth-rce-jfrog-artifactory/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018

Remediation Steps

Update to the latest version where this issue is fixed.