Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-42018

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.

cat cve-2026-42018.json
Vendor
JFrog
Product
Artifactory
CVSS
7.5
EPSS (exploit probability)
9.8%
Status
kev
CISA patch-by (BOD 22-01)
Published

CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory. When anonymous access is disabled on an Artifactory instance, an unauthenticated caller can still obtain an internal anonymous-user token through a flaw in the authentication handling path. That token provides access to resources that should require credentials.

CISA added CVE-2026-42018 to its Known Exploited Vulnerabilities catalog on September 11, 2026, with a remediation deadline of September 25, 2026. Active exploitation was observed before the KEV addition: threat actors are chaining this flaw with additional high and critical-severity Artifactory vulnerabilities to escalate from unauthenticated access to administrative control, then deploying a Rust-written backdoor on self-managed instances.

Fix: Apply patches from JFrog’s security advisories page. Confirm your Artifactory version is at or above the patched release listed there.

NVD record: CVE-2026-42018