Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-42018 2026-09-11

JFrog Artifactory Leaks Anonymous Tokens to Unauthenticated Callers (CVE-2026-42018)

"CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a JFrog Artifactory flaw that hands an internal anonymous-user token to unauthenticated callers…"

CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a JFrog Artifactory flaw that hands an internal anonymous-user token to unauthenticated callers even when anonymous access is switched off.

What Is It

CVE-2026-42018 is an improper authentication flaw (CWE-287) in JFrog Artifactory. Under the right conditions, the server returns an internal anonymous-user token to a caller who has not authenticated, and it does so even when the administrator has explicitly disabled anonymous access. That token can potentially expose sensitive resources hosted in the repository.

It carries a CVSS 3.1 base score of 7.5 (HIGH), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, network-reachable, low complexity, no privileges, no user interaction, with high confidentiality impact and no integrity or availability impact.

Why It Matters

Artifactory is a binary and artifact repository, so the resources behind that token are typically build artifacts, packages, and internal dependencies. The defense operators believe they have in place, anonymous access disabled, does not hold. CISA's SSVC assessment marks the vulnerability as automatable, and it was added to KEV on 2026-09-11 under a 2026-09-25 remediation deadline; the KEV listing is the basis for the exploitation determination on this CVE. Separately, Wiz has published reporting on in-the-wild exploitation of Artifactory covering other CVEs in the product, which speaks to attacker interest in the platform but is not evidence for CVE-2026-42018 specifically.

What's Vulnerable

JFrog Artifactory in the following ranges:

Patch Status

Fixed builds are 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8. CISA's required action is to apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk); follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. Due date: 2026-09-25. Known ransomware campaign use is listed as Unknown, and forensic triage is not required for this entry.

Sources