AI description
CVE-2026-42018 is an improper authentication vulnerability affecting JFrog Artifactory. This flaw allows an unauthenticated caller to obtain an internal anonymous-user token, even when anonymous access is explicitly disabled within the system. The presence of this token could potentially lead to the exposure of sensitive resources within the Artifactory instance. This vulnerability has been observed in active exploitation, often chained with CVE-2026-42016. When combined, these vulnerabilities can enable attackers to escalate privileges and gain administrative control over self-hosted Artifactory servers.
- Description
- JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- Source
- reefs@jfrog.com
- NVD status
- Analyzed
- Products
- artifactory
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
Data from CISA
- Vulnerability name
- JFrog Artifactory Improper Authentication Vulnerability
- Exploit added on
- Sep 11, 2026
- Exploit action due
- Sep 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- reefs@jfrog.com
- CWE-287
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
🔒 #CyberSecurity CISA KEV Alert: CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory) and CVE-2026… "On September 11, 2026, CISA added three new entries to its Known Exploited Vulnerabilities…" 🔗 https://t.co/X1AfHct3vg #CyberSecurity #ThreatIntel #critical #zeroday #
@SecurityAr58409
12 Sept 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-42018: JFrog Artifactory Anonymous Token Leak — CISA KEV Detection and… "On September 11, 2026, CISA added CVE-2026-42018 to the Known Exploited…" 🔗 https://t.co/SQwKWe99yh #CyberSecurity #ThreatIntel #cve202642018 #critical #cisakev
@SecurityAr58409
12 Sept 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA put Artifactory on KEV. The two-bug chain is already live. @CISAgov listed CVE-2026-42016 and CVE-2026-42018 as Known Exploited on 11 Sep (federal due 25 Sep). @wiz_io watched multiple actors chain them against self-hosted @jfrog Artifactory from 15 Aug to 8 Sep: unauth
@hackerlogs
12 Sept 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JFrog Artifactory Fixes Improper Authentication Flaw (CVE-2026-42018) JFrog Artifactory addresses CVE-2026-42018, an improper authentication flaw leaking internal tokens when anonymous access is disabled. Full write-up → link in bio #cybersecurity #infosec #cve #kev #jfrog ht
@HotaSamit
12 Sept 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706
@__kokumoto
12 Sept 2026
515 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
Attackers created admin accounts on exposed Artifactory instances by chaining CVE-2026-42018 and CVE-2026-42016. CVE-2026-42018 lets you pull JWTs for the internal anonymous user even with anonymous access turned off. CVE-2026-42016 then escalates via broken token validation.
@SecureChap
11 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSe
@CISACyber
11 Sept 2026
4490 Impressions
4 Retweets
7 Likes
1 Bookmark
0 Replies
0 Quotes
Attackers are chaining JFrog Artifactory flaws CVE-2026-42018 + CVE-2026-42016 to gain admin access and drop a Rust backdoor. Patch self-hosted instances now. #CyberSecurity #JFrog #InfoSec https://t.co/VcCewBlUr3
@CyberWorldOps
11 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JFrog Artifactory flaws are being chained in the wild to mint admin tokens and plant a Rust backdoor on self-hosted servers. Wiz saw CVE-2026-42018 plus CVE-2026-42016 used Aug 15-Sep 8 to turn an anonymous JWT into admin in under five minutes, then install malicious Groovy
@XavierRiveraX
11 Sept 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.
@Sunil_kumawat17
11 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42
@rst_cloud
11 Sept 2026
112 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB
@yactina1336
10 Sept 2026
62 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "A3362EDD-29B3-4A8E-8C6B-C1E4B6801A7F",
"versionEndExcluding": "7.111.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "95C14B2A-24BF-4C81-A178-BBA744F9AB2A",
"versionEndExcluding": "7.117.27",
"versionStartIncluding": "7.117.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "F3D1E17C-2AE8-4B30-8802-68D75F4937B8",
"versionEndExcluding": "7.125.19",
"versionStartIncluding": "7.125.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "3751FB76-30AC-4EB7-AAC7-7D1A6215C59B",
"versionEndExcluding": "7.133.28",
"versionStartIncluding": "7.133.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "B8DDB685-DD49-4FD8-86C4-2852EBEBD5DE",
"versionEndExcluding": "7.146.8",
"versionStartIncluding": "7.146.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]