CVE-2026-42018
HIGH · 7.5 KEV EPSS 0.9%KEV-listed confirmed exploitation, chaining PoC reported, defenders triaging; EPSS low but exploitation in-the-wild.
What: JFrog Artifactory authentication bypass leaking internal anonymous tokens to unauthenticated users when anonymous access is disabled (CVSS 7.5 HIGH, EPSS 0.28%).
Why it matters: Added to CISA KEV 2026-09-11 as actively exploited. Multiple sources report in-the-wild exploitation, including chaining with CVE-2026-42016 for admin access and Rust backdoor deployment. Vendor patching urgently signaled by defender chatter.
Where it's seen: CISA advisory, security researcher writeups (NetSPI, Wiz), threat intel alerts, mass social amplification. Posts frame as active attack chain affecting self-hosted Artifactory instances with immediate remediation calls.
RISK: CRITICAL — KEV-listed active exploitation with confirmed chaining enabling admin compromise and persistent backdoor.
Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- None
- Availability
- None