CVE-2026-42018

Analyzed
Published: 12 Aug 2026, 17:43
Last modified:11 Sept 2026, 19:58

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.35% LOW
0% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Aug 2026, 17:43
Published
Vulnerability first disclosed
11 Sept 2026, 00:00
Added to CISA KEV
JFrog Artifactory Improper Authentication Vulnerability
11 Sept 2026, 19:58
Last Modified
Vulnerability information updated
25 Sept 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.35% Percentile: 28%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • jfrogartifactory

    < 7.146.8 | < 7.111.20 | ≥ 7.117.0, < 7.117.27 | ≥ 7.125.0, < 7.125.19 | ≥ 7.133.0, < 7.133.28 | ≥ 7.146.0, < 7.146.8

References (4)