Status: KEV
| Advisory ID: CVE-2026-42018
Key Details
| CVE | CVE-2026-42018 |
| Vulnerability Name | JFrog Artifactory Improper Authentication Vulnerability |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | JFrog Artifactory |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-287 (Improper Authentication) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-11. |
| Exploitation prediction (EPSS) | 9.80% probability of exploitation in the next 30 days (95% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
What to Do
Monitor JFrog's web page for any future patch releases. See vendor advisory link below.
References
KEV Required Action