← Vulnerability feed

Vulnerability record · CVE-2026-42018 · published 12 August 2026

CVE-2026-42018: JFrog Artifactory improper authentication leaks anonymous token

Jfrog · Artifactory

JFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token is meant for internal use, its disclosure can expose sensitive resources that should require authentication. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.1 7.5 High.

7.5 CVSS 3.1 High CISA KEV since 11 Sep 2026 EPSS 9.8% · top 4.6% CWE-287 · Improper authentication
7.5CVSS 3.1 base score
9.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
12 Sep 2026Last modified by NVD

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated disclosure of an internal token with high confidentiality impact and is listed in CISA KEV with confirmed in-the-wild exploitation, though EPSS is low.

What it is

JFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token is meant for internal use, its disclosure can expose sensitive resources that should require authentication. The flaw is an improper authentication issue (CWE-287) rated CVSS 3.1 7.5 High.

Impact

An unauthenticated attacker obtains an internal anonymous-user token and can use it to reach resources that the token is authorized for, gaining read access to sensitive data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). Any caller able to send requests to the affected Artifactory service can attempt to trigger the token disclosure.

Exploitation

CVE-2026-42018 is listed in CISA KEV with a due date of 2026-09-25, and a third-party advisory reference describes Artifactory exploitation in the wild. EPSS is low (0.0092, 58th percentile), but KEV listing indicates confirmed real-world exploitation.

What to do

  • Apply the vendor fix from the JFrog security advisories and self-managed release notes; patch to a release that corrects the anonymous token handling.
  • If patching cannot be completed by the CISA due date, follow CISA BOD 26-04 guidance, including discontinuing use of the product where mitigations are unavailable.
  • Restrict network access to Artifactory management and API endpoints so only trusted networks or users can reach them.
  • Review and tighten anonymous access configuration, and audit for any internal tokens that may have been exposed.
  • Monitor vendor advisories for updated guidance, as the record does not specify affected versions.

Detection

  • Search Artifactory access and audit logs for unauthenticated requests that receive token material or unexpected anonymous-user token issuance.
  • Alert on anonymous-user token use against resources that normally require authentication, especially from unfamiliar source IPs.
  • Hunt for requests to Artifactory endpoints from external or untrusted networks that correlate with token retrieval responses.
  • Correlate Artifactory token issuance events with subsequent access to sensitive repositories or configuration data.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog on 11 September 2026 as "JFrog Artifactory Improper Authentication Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 25 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2022-0668Jfrog artifactory improper privilege management vulnerabilityJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is…EPSS 0.63%9.8CVE-2019-17444JFrog Artifactory default admin passwords allow full compromiseJFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials …EPSS 69%analysed9.8CVE-2018-19971Jfrog artifactory insufficient verification of data authenticity vulnerabilityJFrog Artifactory Pro 6.5.9 has Incorrect Access Control.EPSS 3.0%9.8CVE-2019-9733JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-ForArtifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For…EPSS 53%analysed9.8CVE-2016-10036Jfrog artifactory unrestricted file upload vulnerabilityUnrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…EPSS 26%

Source: NIST National Vulnerability Database (record CVE-2026-42018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.