All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-42018
HIGHpublished 2026-08-12 18:17 UTC · 9 hours ago
7.5
CVSS / 10
// description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
// weaknesses (CWE)
- CWE-287