Skip to content
JFrogCVE-2026-42018

JFrog artifactory: improper authentication

High7.5CVE-2026-42018 · Published Aug 12, 2026 · updated Sep 12, 2026

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

JFrog advisory

Affected versions

PackageAffectedFixed in
artifactory
Product
< 7.111.207.111.20
>= 7.117.0, < 7.117.277.117.27
>= 7.125.0, < 7.125.197.125.19
>= 7.133.0, < 7.133.287.133.28
Details and references

More JFrog advisories

All JFrog
Advisory
JFrog artifactory: improper input validation
High8.8Aug 12
JFrog artifactory: missing authorization
Medium4.3Aug 12
JFrog artifactory: insufficient authenticity check
High8.1Aug 12
JFrog artifactory: missing authorization
Medium5.9Aug 12
JFrog artifactory: improper signature check
High7.2Aug 12
JFrog artifactory: missing authorization
Medium6.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.