THREAT OPS › CVEs › CVE-2026-42018
CVE-2026-42018 — JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Vulnerability details
- Affected productsArtifactory
- KEV remediation due2026-09-25
Related reporting
- [NVD] CVE-2026-42018 (HIGH 7.5) — JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.nvd
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-42018 — JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerabilitycisa_kev
- Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329wiz_research