JFrog Artifactory Anonymous User Token Disclosure

high Web App Scanning Plugin ID 115474

Synopsis

JFrog Artifactory Anonymous User Token Disclosure

Description

Self-hosted JFrog Artifactory versions prior to 7.111.21, 7.117.x prior to 7.117.28, 7.125.x prior to 7.125.20, 7.133.x prior to 7.133.29, 7.146.x prior to 7.146.38 and 7.161.x prior to 7.161.20 suffer from an improper authentication vulnerability. The AWS assumed role token exchange endpoint of the JFrog Access service fails to enforce authentication when the request path carries a trailing slash. A remote and unauthenticated attacker can therefore submit a POST request to that endpoint and be granted a valid access token bound to the internal anonymous user, even when anonymous access is disabled on the instance. The disclosed token authenticates against the platform APIs and can be used to enumerate repositories and read the hosted artifacts and the server metadata exposed to that identity. This issue has been observed being chained with CVE-2026-42016 to escalate the disclosed token to an administrator scoped credential.

Solution

Upgrade to JFrog Artifactory version 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 or later.

See Also

https://docs.jfrog.com/releases/docs/jfrog-security-advisories

Plugin Details

Severity: High

ID: 115474

Type: Check Based

Published: 9/14/2026

Updated: 9/14/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 7.3

Percentile: 98.25

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-42018

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS Score Source: CVE-2026-42018

Vulnerability Information

CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/28/2026

Vulnerability Publication Date: 7/29/2026

CISA Known Exploited Vulnerability Due Dates: 9/25/2026

Reference Information

CVE: CVE-2026-42018