DIRAS TAKE
Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation due date; prioritize installing vendor fixes or applying vendor mitigations immediately for internet-facing Artifactory instances.
What is CVE-2026-42018?
An unauthenticated remote attacker can obtain an internal anonymous-user token from JFrog Artifactory, which could allow access to resources intended to be protected. CVE-2026-42018 affects multiple 7.x releases; vendor fixes are available for specific builds. The flaw can be triggered without credentials and requires only network access to the Artifactory service. A successful request may expose sensitive repositories or artifacts when the server erroneously returns an internal anonymous token despite anonymous access being disabled. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of JFrog Artifactory are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | before 7.111.20 | 7.111.20 |
| 7.x | 7.117.0 – before 7.117.27 | 7.117.27 |
| 7.x | 7.125.0 – before 7.125.19 | 7.125.19 |
| 7.x | 7.133.0 – before 7.133.28 | 7.133.28 |
| 7.x | 7.146.0 – before 7.146.8 | 7.146.8 |
Is CVE-2026-42018 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11, and US federal agencies were required to remediate it by 2026-09-25.
How to fix CVE-2026-42018
- Upgrade Artifactory to a fixed build: 7.111.20, 7.117.27, 7.125.19, 7.133.28, or 7.146.8 as appropriate for your branch.
- If you cannot upgrade immediately, restrict network exposure of Artifactory (IP allowlists, firewall rules) and block unauthenticated access to the service.
- Follow JFrog’s published guidance and configuration recommendations for anonymous access and authentication hardening.
- Monitor Artifactory logs and audit access to repositories for unusual anonymous-token activity.
Frequently asked questions
Is CVE-2026-42018 being actively exploited?
CISA added CVE-2026-42018 to its Known Exploited Vulnerabilities catalog on 2026-09-11, and US federal agencies were required to remediate it by 2026-09-25.
Which Artifactory versions are affected by CVE-2026-42018?
The issue affects multiple 7.x series builds before their listed fixes; affected ranges include builds prior to 7.111.20 and the intervals 7.117.0–before 7.117.27, 7.125.0–before 7.125.19, 7.133.0–before 7.133.28, and 7.146.0–before 7.146.8.
Is there a patch for CVE-2026-42018?
Yes. JFrog published fixes in builds 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8 for the affected 7.x branches.
Does CVE-2026-42018 require authentication?
No. The vulnerability can be triggered by an unauthenticated caller; it may return an internal anonymous-user token even when anonymous access is disabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-42018
- cve.org/CVERecord?id=CVE-2026-42018
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
- docs.jfrog.com/releases/docs/jfrog-security-advisories
- docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- All JFrog CVEs on CVE Radar
- CVEs published in September 2026