CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that allows an unauthenticated remote attacker to obtain an internal anonymous-user token even when anonymous access is disabled, exposing sensitive resources. It is actively exploited in the wild (CISA KEV listed), commonly chained with CVE-2026-42016 and CVE-2026-82329 to achieve full administrative control of the Artifactory server.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-12
Added to CISA KEV: 2026-09-11 30 DAYS BETWEEN CVE AND KEV
CVE-2026-42018 is an improper authentication vulnerability affecting JFrog Artifactory that allows an unauthenticated remote attacker to retrieve an internal anonymous-user token, even when anonymous access is explicitly disabled. This vulnerability is critical because it is currently being exploited in the wild, often in conjunction with other vulnerabilities (such as CVE-2026-42016 and CVE-2026-82329) to bypass authentication and gain full administrative control over the affected Artifactory instance [1][2].
An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take administrative control of exposed servers. The flaws, tracked as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, affect multiple Artifactory release .
CVE-2026-42018 is an improper-authentication vulnerability that may cause Artifactory to return an internal anonymous-user token to an ... Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVEβ¦
Wiz Research has identified active exploitation of three JFrog Artifactory vulnerabilities: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining these flaws to bypass authentication and gain administrative control, deploying Rust-based backdoors and malicious Groovy plugins forβ¦
Block or limit network access to the Artifactory API endpoints that could reveal the token through firewall rules or network segmentation until the vendor releases a fix. Generated by OpenCVE AI on August 12, 2026 at 23:25 UTC.