CVE-2026-42018
Anonymous user token generation exposure in JFrog Artifactory
Exploited in the wild. In CISA KEV since 2026‑09‑11. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your JFrog Artifactory is publicly reachable and whether the “anonymous access” setting is disabled by an administrator.
- Verify your Artifactory version and compare it to the fixed releases below.
- Upgrade Artifactory to at least one of the fixed versions: 7.111.20, 7.117.27, 7.125.19, 7.133.28, or 7.146.8.
- If you cannot upgrade immediately, immediately restrict network access to Artifactory (allow only required internal IPs/VPN) until the upgrade is complete.
What it is
From the CVE record
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
In plain language
Written by AI from the recordCVE-2026-42018 is a serious JFrog Artifactory flaw where anyone on the network can request a special anonymous access token and use it to view files that should be hidden, even when anonymous access is turned off. If you run Artifactory, you should act now.
CVE-2026-42018 is an unauthenticated access token exposure in JFrog Artifactory (CWE-287) that allows a network attacker to retrieve a secret anonymous/guest access key and use the returned token to bypass intended access controls and read protected content; it is confirmed in CISA KEV and is being exploited in the wild.
If you're affected
- Confidential file disclosure
- Customer/partner data exposure
- Intellectual property theft
- Compromise of software supply chain
- Potential ransomware staging
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-09-11.
US federal agencies must remediate by 2026-09-25.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
9.8% chance of exploitation activity in the next 30 days, which ranks it in the 95th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
- Attention now
unknown.
Real risk signals with little public attention so far.
Lifecycle
18 events over 43 days, from the signal feeds we watch.
- EPSS band changemoderate → lowepss band change
- EPSS band changelow → moderateepss band change
- Nuclei check added
- Patch availablerecord updated
- Added to CISA KEVpatch available, record updated
- Record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Scored 7.5 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity NoneNo integrity impact
- Availability NoneNo availability impact
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- docs.jfrog.com/releases/docs/jfrog-security-advisories
- docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
And 1 more reference. See all after sign-in
In the news
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
- Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- Artifactory flaws chained in attacks deploying backdoor malware
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Artifactory, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI