CVE-2026-42018, a CVSS 7.5 authentication flaw in JFrog Artifactory, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026 — the same day as its sibling flaw, CVE-2026-42016, in the same product. NVD’s vector shows a network-exploitable flaw requiring no privileges and no user interaction, with high confidentiality impact.
What the vulnerability does
NVD tracks CVE-2026-42018 under CWE-287 (Improper Authentication). Per NVD’s description, JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller even when anonymous access is explicitly disabled on that instance — potentially exposing resources the administrator believed were access-restricted, since the control meant to prevent anonymous access doesn’t actually stop the token from being issued.
Why it’s on KEV
CISA’s September 11 KEV addition requires federal civilian agencies to remediate under BOD 26-04. As with CVE-2026-42016, Wiz’s published research on “Artifactory under attack in the wild” is linked from NVD’s reference data for this CVE too — the same exploitation research covers both flaws together.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone; confidence on severity is marked medium pending independent corroboration. No EPSS score is ingested for this CVE, and we don’t have a specific fixed-version number for CVE-2026-42018 the way CVE-2026-42016’s advisory names 7.133.11 — administrators should verify the remediated version directly against JFrog’s own security advisories page rather than assuming it matches its sibling CVE’s fix version.
Why this matters
An access control an administrator explicitly configured — disabling anonymous access — silently failing to actually prevent anonymous token issuance is a particularly deceptive class of bug: the instance looks correctly locked down in its configuration, while remaining exposed in practice. Combined with CVE-2026-42016’s token-scope validation gap, a full compromise chain is plausible on unpatched instances: obtain an anonymous token via this flaw, then use scope-validation weaknesses to escalate what that token can access. Treat both CVEs as one upgrade decision for any Artifactory Self-Hosted deployment.
Frequently Asked Questions
What is CVE-2026-42018? A CVSS 7.5 improper-authentication vulnerability in JFrog Artifactory that can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled.
Is CVE-2026-42018 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026.
Is this related to CVE-2026-42016? Yes — both affect JFrog Artifactory, were added to CISA KEV the same day, and are covered together in Wiz’s exploitation research.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 15, 2026. See more vulnerability intelligence.