← back

CVE-2026-42018

HIGH · 7.5 KEV EPSS 0.9%
hype LIKELY HACK · 82 hack

KEV-listed confirmed exploitation, chaining PoC reported, defenders triaging; EPSS low but exploitation in-the-wild.

What: JFrog Artifactory authentication bypass leaking internal anonymous tokens to unauthenticated users when anonymous access is disabled (CVSS 7.5 HIGH, EPSS 0.28%).

Why it matters: Added to CISA KEV 2026-09-11 as actively exploited. Multiple sources report in-the-wild exploitation, including chaining with CVE-2026-42016 for admin access and Rust backdoor deployment. Vendor patching urgently signaled by defender chatter.

Where it's seen: CISA advisory, security researcher writeups (NetSPI, Wiz), threat intel alerts, mass social amplification. Posts frame as active attack chain affecting self-hosted Artifactory instances with immediate remediation calls.

RISK: CRITICAL — KEV-listed active exploitation with confirmed chaining enabling admin compromise and persistent backdoor.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/12/2026, 7:53:08 AM

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 3.6
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Weaknesses