GPU VulnDB

Database/Control plane, storage & DevOps

JFrog Artifactory: internal anonymous-user token returned to unauthenticated callers

CVSS 7.5CVE-2026-42018Control plane, storage & DevOpsKnown exploitedcurated

Impact

Artifactory can hand an internal anonymous-user token to an unauthenticated caller even when anonymous access is turned off, exposing resources the operator believed were closed. For a registry that fronts container images, driver packages and model artifacts for a GPU fleet, that is unauthenticated read of repository contents that were meant to require login. It is tracked separately from CVE-2026-42016 - different mechanism, different fix - but the two are being exploited together in the wild and both are in the KEV catalogue.

Who can reach it

Any unauthenticated caller who can reach the Artifactory HTTP endpoint. No credentials, no user interaction.

What to do

Apply the JFrog fixed release from the self-managed release notes and restart the service; the advisory pages linked below carry the version. Until patched, restrict network reach to Artifactory to known CI and cluster ranges. Because exploitation is confirmed in the wild, review access logs for anonymous-token use and rotate anything a leaked read could have exposed.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.