Database/Control plane, storage & DevOps
JFrog Artifactory: internal anonymous-user token returned to unauthenticated callers
Impact
Artifactory can hand an internal anonymous-user token to an unauthenticated caller even when anonymous access is turned off, exposing resources the operator believed were closed. For a registry that fronts container images, driver packages and model artifacts for a GPU fleet, that is unauthenticated read of repository contents that were meant to require login. It is tracked separately from CVE-2026-42016 - different mechanism, different fix - but the two are being exploited together in the wild and both are in the KEV catalogue.
Who can reach it
Any unauthenticated caller who can reach the Artifactory HTTP endpoint. No credentials, no user interaction.
What to do
Apply the JFrog fixed release from the self-managed release notes and restart the service; the advisory pages linked below carry the version. Until patched, restrict network reach to Artifactory to known CI and cluster ranges. Because exploitation is confirmed in the wild, review access logs for anonymous-token use and rotate anything a leaked read could have exposed.
References
Related entries
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointCVE-2026-42151 · Prometheus (Azure AD remote-write OAuth client_secret in /-/config)High
- Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memoryCVE-2026-42154 · Prometheus (/api/v1/read snappy decompression length handling)High
- OpenTelemetry JS Prometheus exporter: a malformed request URI crashes the whole Node.js processCVE-2026-44902 · OpenTelemetry JS Prometheus exporter (@opentelemetry/exporter-prometheus, also via sdk-node)High
- rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinksCVE-2026-54572 · rclone (local backend, --links)High
- Jenkins Script Security Plugin: Groovy sandbox escape via AST annotation extensions memberCVE-2026-57281 · Jenkins Script Security Plugin (Groovy sandbox, AST transformation annotations)High
- GitLab CE/EE: improper input validation lets an unauthenticated user cause a denial of serviceCVE-2026-7427 · GitLab CE/EE (unauthenticated request path, improper input validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.