JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory returns an internal anonymous-user token to unauthenticated callers even when anonymous access is disabled, allowing unauthorized resource access and enabling privilege escalation chains.
- Vendor
- JFrog
- Product
- Artifactory
- CVSS
- 7.5
- EPSS (exploit probability)
- 9.8%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory. When anonymous access is disabled on an Artifactory instance, an unauthenticated caller can still obtain an internal anonymous-user token through a flaw in the authentication handling path. That token provides access to resources that should require credentials.
CISA added CVE-2026-42018 to its Known Exploited Vulnerabilities catalog on September 11, 2026, with a remediation deadline of September 25, 2026. Active exploitation was observed before the KEV addition: threat actors are chaining this flaw with additional high and critical-severity Artifactory vulnerabilities to escalate from unauthenticated access to administrative control, then deploying a Rust-written backdoor on self-managed instances.
Fix: Apply patches from JFrog’s security advisories page. Confirm your Artifactory version is at or above the patched release listed there.
NVD record: CVE-2026-42018
