CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog on 2026-09-11, confirming active exploitation of a JFrog Artifactory flaw that hands an internal anonymous-user token to unauthenticated callers even when anonymous access is switched off.
What Is It
CVE-2026-42018 is an improper authentication flaw (CWE-287) in JFrog Artifactory. Under the right conditions, the server returns an internal anonymous-user token to a caller who has not authenticated, and it does so even when the administrator has explicitly disabled anonymous access. That token can potentially expose sensitive resources hosted in the repository.
It carries a CVSS 3.1 base score of 7.5 (HIGH), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, network-reachable, low complexity, no privileges, no user interaction, with high confidentiality impact and no integrity or availability impact.
Why It Matters
Artifactory is a binary and artifact repository, so the resources behind that token are typically build artifacts, packages, and internal dependencies. The defense operators believe they have in place, anonymous access disabled, does not hold. CISA's SSVC assessment marks the vulnerability as automatable, and it was added to KEV on 2026-09-11 under a 2026-09-25 remediation deadline; the KEV listing is the basis for the exploitation determination on this CVE. Separately, Wiz has published reporting on in-the-wild exploitation of Artifactory covering other CVEs in the product, which speaks to attacker interest in the platform but is not evidence for CVE-2026-42018 specifically.
What's Vulnerable
JFrog Artifactory in the following ranges:
- Below 7.111.20
- 7.117.0 up to (not including) 7.117.27
- 7.125.0 up to (not including) 7.125.19
- 7.133.0 up to (not including) 7.133.28
- 7.146.0 up to (not including) 7.146.8
Patch Status
Fixed builds are 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8. CISA's required action is to apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk); follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. Due date: 2026-09-25. Known ransomware campaign use is listed as Unknown, and forensic triage is not required for this entry.
Sources
- CISA KEV Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
- NVD, CVE-2026-42018, https://nvd.nist.gov/vuln/detail/CVE-2026-42018
- JFrog Security Advisories; https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- JFrog Artifactory Self-Managed Releases; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- Wiz, Artifactory Under Attack: In-the-Wild Exploitation (covers other Artifactory CVEs, not CVE-2026-42018), https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk