JFrog Artifactory Anonymous-Token Authentication Bypass Chained with Privilege Escalation - Actively Exploited (CVE-2026-42018)
Release Date: 11th September 2026
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that operate a self-hosted JFrog Artifactory instance. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-42018 is a high-severity authentication flaw in JFrog Artifactory, a widely-used enterprise binary/artifact repository manager (CERTVU has previously judged JFrog Artifactory relevant to Vanuatu - see Advisory 240, CVE-2026-82329).
What are the systems affected?
The following version(s) are affected:
JFrog Artifactory prior to 7.111.20, and 7.117.0–7.117.26, 7.125.0–7.125.18, 7.133.0–7.133.27, and 7.146.0–7.146.7 – (Affected)
JFrog Artifactory 7.111.20, 7.117.27, 7.125.19, 7.133.28, 7.146.8, and later on each respective branch – (Not affected, patched)
What does this mean?
Typical attack flow:
- Obtain an internal anonymous-user token without authenticating — A remote, unauthenticated attacker sends a crafted HTTP request (observed as a POST to "/access/api/v1/aws/token/" with a trailing slash) to a reachable Artifactory instance, which improperly returns a valid internal anonymous-user access token even though anonymous access is disabled.
- Escalate the anonymous token to administrator scope and plant a backdoor — Where the instance is also vulnerable to the companion privilege-escalation flaw, CVE-2026-42016, the attacker exchanges the low-privileged anonymous token for one with administrator scope, creates new administrator accounts, and installs persistent backdoors.
Attack vectors:
- A network-based, unauthenticated attack against any reachable JFrog Artifactory instance, exploiting a crafted HTTP request that returns a valid internal anonymous-user access token even though anonymous access is disabled.
- No authentication or user interaction is required, and CVE-2026-42018 is being actively exploited in the wild.
Successful exploitation may allow attackers to:
- Obtain a valid internal anonymous-user access token without authenticating, even when anonymous access is disabled.
- Where chained with the companion privilege-escalation flaw (CVE-2026-42016), escalate the token to administrator scope, create new administrator accounts, and install persistent backdoors.
Mitigation process?
CERTVU recommends the following:
-
Apply the Vendor Patch Immediately
Upgrade JFrog Artifactory to the fixed version for your release branch (7.111.20, 7.117.27, 7.125.19, 7.133.28, or 7.146.8, or later), and separately confirm you are also running 7.133.11 or later to close the CVE-2026-42016 escalation path this flaw is actively chained with. -
Restrict Network Access Where Patching Is Delayed
Restrict network access to the Artifactory instance where patching must be delayed. -
Audit for Prior Compromise
Audit for signs of prior compromise before and after patching. -
Rotate Credentials and Hunt for Backdoors
Rotate credentials and hunt for planted backdoors.
Report any suspected compromise of a JFrog Artifactory instance to CERTVU at