• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-42018: improper authentication in JFrog Artifactory

An unauthenticated remote attacker can obtain an internal anonymous-user token from JFrog Artifactory, which could allow access to resources intended to be protected. CVE-2026-42018 affects multiple 7.x releases; vendor fixes are available for specific builds. The flaw can be triggered without credentials and requires only network access to the Artifactory service. A successful request may expose sensitive repositories or artifacts when the server erroneously returns an internal anonymous token despite anonymous access being disabled.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.5HIGH
EPSS
0.09805
CWE
CWE-287
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation due date; prioritize installing vendor fixes or applying vendor mitigations immediately for internet-facing Artifactory instances.

What is CVE-2026-42018?

An unauthenticated remote attacker can obtain an internal anonymous-user token from JFrog Artifactory, which could allow access to resources intended to be protected. CVE-2026-42018 affects multiple 7.x releases; vendor fixes are available for specific builds. The flaw can be triggered without credentials and requires only network access to the Artifactory service. A successful request may expose sensitive repositories or artifacts when the server erroneously returns an internal anonymous token despite anonymous access being disabled. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Which versions of JFrog Artifactory are affected?

BRANCHAFFECTEDFIXED
7.xbefore 7.111.207.111.20
7.x7.117.0 – before 7.117.277.117.27
7.x7.125.0 – before 7.125.197.125.19
7.x7.133.0 – before 7.133.287.133.28
7.x7.146.0 – before 7.146.87.146.8

Is CVE-2026-42018 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11, and US federal agencies were required to remediate it by 2026-09-25.

How to fix CVE-2026-42018

  1. Upgrade Artifactory to a fixed build: 7.111.20, 7.117.27, 7.125.19, 7.133.28, or 7.146.8 as appropriate for your branch.
  2. If you cannot upgrade immediately, restrict network exposure of Artifactory (IP allowlists, firewall rules) and block unauthenticated access to the service.
  3. Follow JFrog’s published guidance and configuration recommendations for anonymous access and authentication hardening.
  4. Monitor Artifactory logs and audit access to repositories for unusual anonymous-token activity.

Frequently asked questions

Is CVE-2026-42018 being actively exploited?

CISA added CVE-2026-42018 to its Known Exploited Vulnerabilities catalog on 2026-09-11, and US federal agencies were required to remediate it by 2026-09-25.

Which Artifactory versions are affected by CVE-2026-42018?

The issue affects multiple 7.x series builds before their listed fixes; affected ranges include builds prior to 7.111.20 and the intervals 7.117.0–before 7.117.27, 7.125.0–before 7.125.19, 7.133.0–before 7.133.28, and 7.146.0–before 7.146.8.

Is there a patch for CVE-2026-42018?

Yes. JFrog published fixes in builds 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8 for the affected 7.x branches.

Does CVE-2026-42018 require authentication?

No. The vulnerability can be triggered by an unauthenticated caller; it may return an internal anonymous-user token even when anonymous access is disabled.

References