CVE-2026-42018
JFrog Artifactory returns an internal anonymous-user token to an unauthenticated caller even when anonymous access is DISABLED (CISA KEV, exploited in the wild)
- Severity
- high
- Affected product
- JFrog Artifactory
- Affected versions
- JFrog Artifactory < 7.111.20
- Affected versions
- JFrog Artifactory ≥ 7.117.0, < 7.117.27
- Affected versions
- JFrog Artifactory ≥ 7.125.0, < 7.125.19
- Affected versions
- JFrog Artifactory ≥ 7.133.0, < 7.133.28
- Affected versions
- JFrog Artifactory ≥ 7.146.0, < 7.146.8
- Fixed in
- JFrog Artifactory 7.111.20
- Fixed in
- JFrog Artifactory 7.117.27
- Fixed in
- JFrog Artifactory 7.125.19
- Fixed in
- JFrog Artifactory 7.133.28
- Fixed in
- JFrog Artifactory 7.146.8
- Added to NewScan
- 2026-09-14
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints JFrog Artifactory from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-13. CISA KEV, CVSS 7.5, exploited in the wild alongside CVE-2026-42016. The operator turned anonymous access OFF and the server still hands an internal anonymous-user token to a caller who presents nothing, so the control that was supposed to close the instance is the control being bypassed - which is what makes it worth a row even though the impact reads as information disclosure. FIVE ROWS for this one id, one per maintenance branch, because NVD gives five disjoint arms (read live from the API 2026-09-13): `lt 7.111.20`, then `ge 7.117.0 lt 7.117.27`, `ge 7.125.0 lt 7.125.19`, `ge 7.133.0 lt 7.133.28`, `ge 7.146.0 lt 7.146.8`. A single merged `lt 7.146.8` would call a PATCHED 7.117.27 vulnerable - the gap between arms is real, patched territory, not a rounding error - and that is the failure mode /daily-cve section 5b calls worse than no gate at all. Multi-arm rows for one id are the shipped pattern here (Metabase carries twelve for CVE-2026-72898). This row is the first arm, everything below 7.111.20. Version-match only: the proof is retrieving a token from someone else's repository. Version source and live measurement as for the CVE-2026-42016 row above - the measured 7.161.26 build is above every arm, so it is the patched arm on all five.
COMPONENT VERSION RANGE
NewScan fingerprints JFrog Artifactory from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-13. The 7.117 maintenance branch arm of CVE-2026-42018 - see the `lt 7.111.20` row above for the mechanism, the KEV status and why the five arms are not merged. `ge` inclusive and `lt` exclusive exactly as NVD states them.
COMPONENT VERSION RANGE
NewScan fingerprints JFrog Artifactory from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-13. The 7.125 maintenance branch arm of CVE-2026-42018 - see the `lt 7.111.20` row for the mechanism and why the arms stay separate.
COMPONENT VERSION RANGE
NewScan fingerprints JFrog Artifactory from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-13. The 7.133 maintenance branch arm of CVE-2026-42018 - see the `lt 7.111.20` row for the mechanism and why the arms stay separate. Note this branch also carries CVE-2026-42016 below 7.133.11, so a 7.133.5 install reports both ids, which is correct: they are two different bugs with two different fix points on the same branch.
COMPONENT VERSION RANGE
NewScan fingerprints JFrog Artifactory from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-13. The 7.146 maintenance branch arm of CVE-2026-42018, the newest arm NVD lists - see the `lt 7.111.20` row for the mechanism and why the arms stay separate.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →