Junglewise Threat Intelligence

CVE-2026-42018: JFrog Artifactory improper authentication vulnerability

CVE-2026-42018 · Severity: critical · Exploited in the wild · Published 2026-09-11

Executive brief

JFrog Artifactory is a widely-used artifact repository platform that manages software binaries and build artifacts for organizations. This vulnerability allows an unauthenticated attacker to obtain an internal anonymous-user token even when anonymous access is disabled, potentially gaining unauthorized access to sensitive artifacts, build information, and dependencies. This could enable supply chain attacks, intellectual property theft, or deployment of malicious artifacts.

Technical details

JFrog Artifactory contains an improper authentication vulnerability in its token issuance mechanism. The vulnerability allows an unauthenticated attacker to request an internal anonymous-user token even when anonymous access is explicitly disabled in the configuration. The flaw stems from insufficient validation of authentication state during token generation. Attackers can exploit this over the network without authentication or user interaction to obtain valid tokens that grant access to the repository. Successful exploitation enables unauthorized access to private artifacts, metadata, and build information. This vulnerability has been observed being actively exploited in the wild. Patches are available from JFrog.

Affected products

  • JFrog Artifactory

Timeline

  • 2026-09-11: disclosed
  • exploited: Reported exploited in the wild

Related threats