Vulnerability
Published 2026-09-10
Verified 2026-09-19

JFrog Artifactory CVE-2026-42018: anonymous-user token leak (chained in wild with CVE-2026-42016)

Wiz Research (10 September 2026) documents in-the-wild chaining of CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between 15 August and 8 September 2026, often dropping a custom Rust C2 backdoor. CVE-2026-42018 is an authentication flaw that can return an internal anonymous-user token to an unauthenticated requester even when anonymous access is disabled. Alone it is not admin; chained with CVE-2026-42016 (token scope / privilege escalation) Wiz saw unauthenticated requests become admin-scoped tokens, with follow-on admin account creation, malicious Groovy plugins, and Rust backdoors. Remediated builds per Wiz table include 7.111.20+, 7.117.28, 7.125.20, 7.133.29, 7.146.9+ (and Wiz’s broader “upgrade to 7.111.21 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.38 / 7.161.20 or later” guidance for the chain). Distinct from desk card cve-2026-82329 (also abused). Primary: Wiz; also JFrog advisories. UPDATE 11 September 2026: CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog (dateAdded 2026-09-11; catalogVersion 2026.09.11). Prioritise patching self-hosted Artifactory under BOD 26-04-style exploited-first triage; hunt anonymous/admin tokens, Groovy plugins, and Rust C2 per Wiz.

Product
JFrog Artifactory (self-hosted)
Versions
Impacted per Wiz: prior to 7.111.20; 7.117.0–7.117.27; 7.125.0–7.125.19; 7.133.0–7.133.28; 7.146.0–7.146.8 — remediate 7.111.20 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.9+
Exploited in Australia?
unknown
Patch to
Upgrade self-hosted Artifactory per JFrog/Wiz fixed trains; hunt admin anomalies, Groovy plugins, unexpected tokens

Primary: Wiz — Artifactory under attack (10 Sep 2026) · Vendor: JFrog security advisories · CVE: CVE-2026-42018, CVE-2026-42016, CVE-2026-82329 · The Hacker News (11 Sep 2026)

vulnerabilities cloud