CVE-2026-42018
Artifactory vulnerability analysis and mitigation

Overview

CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that causes the platform to return an internal anonymous-user token to unauthenticated callers even when anonymous access is explicitly disabled. Disclosed on August 12, 2026, by JFrog (acting as CNA), it affects Artifactory Self-Managed versions below 7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, and 7.146.0–7.146.8. JFrog Cloud environments were remediated automatically. It carries a CVSS v3.1 base score of 7.5 (High) (JFrog Advisory, Github Advisory).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication). The root cause is that Artifactory's token-generation logic fails to properly enforce the anonymous access setting: even when anonymous access is disabled, certain unauthenticated API requests trigger the issuance of an internal anonymous-user token that is then returned in the response. An unauthenticated network attacker can exploit this with a low-complexity, no-interaction HTTP request — no credentials or special privileges are required. The flaw is automatable, meaning it can be scripted at scale against exposed Artifactory instances (JFrog Advisory, Github Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to obtain an internal anonymous-user token, which may then be used to access sensitive resources within Artifactory that should be protected behind authentication. The primary impact is a high confidentiality breach — artifacts, package metadata, and repository contents accessible to the anonymous user role may be exposed. Integrity and availability are not directly impacted by this vulnerability, but the leaked token could facilitate further unauthorized actions depending on the permissions associated with the anonymous user role in the target environment (JFrog Advisory, Github Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). CISA's SSVC assessment classifies the vulnerability as automatable with partial technical impact and no known exploitation at this time. The EPSS score is approximately 0.298% (22nd percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A technical write-up by NetSPI titled "Stealing the Artifact" was published shortly after disclosure, which may lower the barrier to exploitation (NetSPI Blog).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible JFrog Artifactory Self-Managed instances running affected versions (below 7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, or 7.146.0–7.146.8) using tools like Shodan, Censys, or direct network scanning.
  2. Identify anonymous access status: Confirm that the target instance has anonymous access disabled (the vulnerable condition) by observing that standard unauthenticated requests to protected endpoints return 401/403 errors.
  3. Send crafted unauthenticated request: Issue a specific unauthenticated HTTP request to the Artifactory API endpoint that triggers the internal anonymous-user token generation logic, exploiting the improper authentication check.
  4. Capture the token: Extract the internal anonymous-user token returned in the server response.
  5. Access sensitive resources: Use the obtained token in subsequent API requests (e.g., Authorization: Bearer <token>) to access artifacts, repository metadata, or other resources that the anonymous user role has permissions to read within the Artifactory instance (JFrog Advisory, NetSPI Blog).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to Artifactory API endpoints that return 200 responses with token data rather than 401/403; repeated requests from the same IP to token-related endpoints without prior authentication.
  • Logs: Artifactory access logs showing unauthenticated requests that result in token issuance (look for requests with no Authorization header that receive a successful response containing token material); anomalous API activity from the anonymous user account when anonymous access is configured as disabled.
  • Behavioral: Subsequent API calls using a bearer token that was not issued through normal login flows; access to artifacts or repository paths by the anonymous user identity when anonymous access is supposed to be disabled (JFrog Advisory).

Mitigation and workarounds

JFrog has released patched versions for all affected release branches: 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8. JFrog Cloud environments have already been automatically remediated and require no action. Self-hosted users should upgrade to the applicable fixed version for their release branch as the primary remediation. As an interim measure, restricting network access to Artifactory to trusted networks and monitoring for anomalous anonymous-user token usage can reduce exposure until patching is complete (JFrog Advisory, JFrog Self-Managed Releases).

Community reactions

NetSPI published a technical blog post titled "Stealing the Artifact: JFrog Artifactory Vulnerability" shortly after disclosure, providing a detailed analysis of the vulnerability and its exploitation mechanics (NetSPI Blog). An independent researcher (Hendry Adrian) also published a write-up covering the same vulnerability (Hendry Adrian Blog). The vulnerability was disclosed as part of a large batch of Artifactory security advisories released by JFrog on August 12, 2026, covering over 20 CVEs, which drew notable attention from the security community given the breadth of issues addressed.

Additional resources


SourceThis report was generated using AI

Related Artifactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69106HIGH8.8
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69105HIGH8.1
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-42018HIGH7.5
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-69107MEDIUM5.9
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026
CVE-2026-70547MEDIUM4.3
  • Artifactory logoArtifactory
  • cpe:2.3:a:jfrog:artifactory
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management