Skip to main content
QUIETLYTIC
Vulnerability

JFrog Artifactory Self-Hosted Authentication Bypass (CVE-2026-42018)

CVE-2026-42018 can leak an internal anonymous-user token to unauthenticated callers in JFrog Artifactory even when anonymous access is disabled. Added to CISA KEV Sept. 11, 2026.

CVE-2026-42018
Threat Level
HIGH
CVSS
7.5
Status
Active Exploitation
Confidence
Medium
Affected Products
JFrog Artifactory Self-Hosted

CVE-2026-42018, a CVSS 7.5 authentication flaw in JFrog Artifactory, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026 — the same day as its sibling flaw, CVE-2026-42016, in the same product. NVD’s vector shows a network-exploitable flaw requiring no privileges and no user interaction, with high confidentiality impact.

What the vulnerability does

NVD tracks CVE-2026-42018 under CWE-287 (Improper Authentication). Per NVD’s description, JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller even when anonymous access is explicitly disabled on that instance — potentially exposing resources the administrator believed were access-restricted, since the control meant to prevent anonymous access doesn’t actually stop the token from being issued.

Why it’s on KEV

CISA’s September 11 KEV addition requires federal civilian agencies to remediate under BOD 26-04. As with CVE-2026-42016, Wiz’s published research on “Artifactory under attack in the wild” is linked from NVD’s reference data for this CVE too — the same exploitation research covers both flaws together.

What we don’t yet have

CVSS scoring and the vulnerability description trace to NVD alone; confidence on severity is marked medium pending independent corroboration. No EPSS score is ingested for this CVE, and we don’t have a specific fixed-version number for CVE-2026-42018 the way CVE-2026-42016’s advisory names 7.133.11 — administrators should verify the remediated version directly against JFrog’s own security advisories page rather than assuming it matches its sibling CVE’s fix version.

Why this matters

An access control an administrator explicitly configured — disabling anonymous access — silently failing to actually prevent anonymous token issuance is a particularly deceptive class of bug: the instance looks correctly locked down in its configuration, while remaining exposed in practice. Combined with CVE-2026-42016’s token-scope validation gap, a full compromise chain is plausible on unpatched instances: obtain an anonymous token via this flaw, then use scope-validation weaknesses to escalate what that token can access. Treat both CVEs as one upgrade decision for any Artifactory Self-Hosted deployment.

Frequently Asked Questions

What is CVE-2026-42018? A CVSS 7.5 improper-authentication vulnerability in JFrog Artifactory that can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled.

Is CVE-2026-42018 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026.

Is this related to CVE-2026-42016? Yes — both affect JFrog Artifactory, were added to CISA KEV the same day, and are covered together in Wiz’s exploitation research.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 15, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools