Administrator actions performed under token:anonymous identity (JFrog Artifactory)
Detects administrator-privileged actions in JFrog Artifactory audit logs attributed to the 'token:anonymous' identity, the tell-tale signature left when CVE-2026-42018 (unauthenticated token retrieval) is chained with CVE-2026-42016 (privilege escalation) to mint an admin-scope token that retains the anonymous username. Also relevant to CVE-2026-82329 authentication bypass activity.
Microsoft Sentinel (KQL)

