Back

HIGH KEV

Anonymous user token generation exposure in JFrog Artifactory

Published Aug 12, 2026 ·Due Sep 25, 2026

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (6)
  1. CISA ADP
    • SSVC exploitation changed from none to active
  2. CISA ADP
    • SSVC exploitation changed from active to none
  3. CISA ADP
    • SSVC exploitation changed from none to active
  4. CISA ADP
    • SSVC exploitation changed from active to none
  5. CISA ADP
    • SSVC exploitation changed from none to active
  6. CISA ADP
    • SSVC exploitation changed from active to none
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner JFROG
Published Aug 12, 2026
Updated Oct 1, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Analyzed
Modified Sep 12, 2026
Red Hat
Severity n/a
Public date n/a