CVE-2026-42018

Published Aug 12, 2026

Last updated 8 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42018 is an improper authentication vulnerability affecting JFrog Artifactory. This flaw allows an unauthenticated caller to obtain an internal anonymous-user token, even when anonymous access is explicitly disabled within the system. The presence of this token could potentially lead to the exposure of sensitive resources within the Artifactory instance. This vulnerability has been observed in active exploitation, often chained with CVE-2026-42016. When combined, these vulnerabilities can enable attackers to escalate privileges and gain administrative control over self-hosted Artifactory servers.

Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Source
reefs@jfrog.com
NVD status
Analyzed
Products
artifactory

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
JFrog Artifactory Improper Authentication Vulnerability
Exploit added on
Sep 11, 2026
Exploit action due
Sep 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

reefs@jfrog.com
CWE-287

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

  1. 🔒 #CyberSecurity CISA KEV Alert: CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory) and CVE-2026… "On September 11, 2026, CISA added three new entries to its Known Exploited Vulnerabilities…" 🔗 https://t.co/X1AfHct3vg #CyberSecurity #ThreatIntel #critical #zeroday #

    @SecurityAr58409

    12 Sept 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔒 #CyberSecurity CVE-2026-42018: JFrog Artifactory Anonymous Token Leak — CISA KEV Detection and… "On September 11, 2026, CISA added CVE-2026-42018 to the Known Exploited…" 🔗 https://t.co/SQwKWe99yh #CyberSecurity #ThreatIntel #cve202642018 #critical #cisakev

    @SecurityAr58409

    12 Sept 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA put Artifactory on KEV. The two-bug chain is already live. @CISAgov listed CVE-2026-42016 and CVE-2026-42018 as Known Exploited on 11 Sep (federal due 25 Sep). @wiz_io watched multiple actors chain them against self-hosted @jfrog Artifactory from 15 Aug to 8 Sep: unauth

    @hackerlogs

    12 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. JFrog Artifactory Fixes Improper Authentication Flaw (CVE-2026-42018) JFrog Artifactory addresses CVE-2026-42018, an improper authentication flaw leaking internal tokens when anonymous access is disabled. Full write-up → link in bio #cybersecurity #infosec #cve #kev #jfrog ht

    @HotaSamit

    12 Sept 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706

    @__kokumoto

    12 Sept 2026

    515 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Attackers created admin accounts on exposed Artifactory instances by chaining CVE-2026-42018 and CVE-2026-42016. CVE-2026-42018 lets you pull JWTs for the internal anonymous user even with anonymous access turned off. CVE-2026-42016 then escalates via broken token validation.

    @SecureChap

    11 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSe

    @CISACyber

    11 Sept 2026

    4490 Impressions

    4 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. Attackers are chaining JFrog Artifactory flaws CVE-2026-42018 + CVE-2026-42016 to gain admin access and drop a Rust backdoor. Patch self-hosted instances now. #CyberSecurity #JFrog #InfoSec https://t.co/VcCewBlUr3

    @CyberWorldOps

    11 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. JFrog Artifactory flaws are being chained in the wild to mint admin tokens and plant a Rust backdoor on self-hosted servers. Wiz saw CVE-2026-42018 plus CVE-2026-42016 used Aug 15-Sep 8 to turn an anonymous JWT into admin in under five minutes, then install malicious Groovy

    @XavierRiveraX

    11 Sept 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Wiz: self-hosted Artifactory chains CVE-2026-42018→CVE-2026-42016 mint admin tokens in <5 min (token:anonymous). CVE-2026-82329 (9.8) still hits unpatched branches alone. Cloud: fine. Self-hosted: upgrade + rotate join keys/tokens. A patch does not revoke minted admins.

    @Sunil_kumawat17

    11 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. #threatreport #LowCompleteness Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | 11-09-2026 Source: https://t.co/fWE1i6K7X8 Key details below ↓ 🎯Victims: Organizations running jfrog artifactory 🔓CVEs: CVE-2026-42

    @rst_cloud

    11 Sept 2026

    112 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog https://t.co/IsrwJJyUoB

    @yactina1336

    10 Sept 2026

    62 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations