
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that causes the platform to return an internal anonymous-user token to unauthenticated callers even when anonymous access is explicitly disabled. Disclosed on August 12, 2026, by JFrog (acting as CNA), it affects Artifactory Self-Managed versions below 7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, and 7.146.0–7.146.8. JFrog Cloud environments were remediated automatically. It carries a CVSS v3.1 base score of 7.5 (High) (JFrog Advisory, Github Advisory).
The vulnerability is classified as CWE-287 (Improper Authentication). The root cause is that Artifactory's token-generation logic fails to properly enforce the anonymous access setting: even when anonymous access is disabled, certain unauthenticated API requests trigger the issuance of an internal anonymous-user token that is then returned in the response. An unauthenticated network attacker can exploit this with a low-complexity, no-interaction HTTP request — no credentials or special privileges are required. The flaw is automatable, meaning it can be scripted at scale against exposed Artifactory instances (JFrog Advisory, Github Advisory).
Successful exploitation allows an unauthenticated attacker to obtain an internal anonymous-user token, which may then be used to access sensitive resources within Artifactory that should be protected behind authentication. The primary impact is a high confidentiality breach — artifacts, package metadata, and repository contents accessible to the anonymous user role may be exposed. Integrity and availability are not directly impacted by this vulnerability, but the leaked token could facilitate further unauthorized actions depending on the permissions associated with the anonymous user role in the target environment (JFrog Advisory, Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). CISA's SSVC assessment classifies the vulnerability as automatable with partial technical impact and no known exploitation at this time. The EPSS score is approximately 0.298% (22nd percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A technical write-up by NetSPI titled "Stealing the Artifact" was published shortly after disclosure, which may lower the barrier to exploitation (NetSPI Blog).
Authorization: Bearer <token>) to access artifacts, repository metadata, or other resources that the anonymous user role has permissions to read within the Artifactory instance (JFrog Advisory, NetSPI Blog).Authorization header that receive a successful response containing token material); anomalous API activity from the anonymous user account when anonymous access is configured as disabled.JFrog has released patched versions for all affected release branches: 7.111.20, 7.117.27, 7.125.19, 7.133.28, and 7.146.8. JFrog Cloud environments have already been automatically remediated and require no action. Self-hosted users should upgrade to the applicable fixed version for their release branch as the primary remediation. As an interim measure, restricting network access to Artifactory to trusted networks and monitoring for anomalous anonymous-user token usage can reduce exposure until patching is complete (JFrog Advisory, JFrog Self-Managed Releases).
NetSPI published a technical blog post titled "Stealing the Artifact: JFrog Artifactory Vulnerability" shortly after disclosure, providing a detailed analysis of the vulnerability and its exploitation mechanics (NetSPI Blog). An independent researcher (Hendry Adrian) also published a write-up covering the same vulnerability (Hendry Adrian Blog). The vulnerability was disclosed as part of a large batch of Artifactory security advisories released by JFrog on August 12, 2026, covering over 20 CVEs, which drew notable attention from the security community given the breadth of issues addressed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."