artifactory vulnerability

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Published 12 Aug 2026Updated 11 Sep 20265 sources
CVSS 7.5 △ CISA KEV

What happened

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Affected versions

artifactory: before 7.111.20 (custom); 7.117.0 through before 7.117.27 (custom); 7.125.0 through before 7.125.19 (custom); 7.133.0 through before 7.133.28 (custom); 7.146.0 through before 7.146.8 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.