{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-9A0FBC5F",
  "slug": "cve-2026-42018-artifactory-anonymous-token-kev-chain",
  "title": "Artifactory anonymous token chain (CISA KEV)",
  "aliases": [
    "CVE-2026-42018",
    "Artifactory anonymous token exposure",
    "CVE-2026-42016"
  ],
  "summary": "Self-hosted JFrog Artifactory could hand an internal anonymous-user token to an unauthenticated caller even when anonymous access was disabled, opening a path into sensitive resources. CISA KEV and public in-the-wild reporting apply. Upgrade past the fixed builds for your Artifactory train and rotate credentials if exposure is plausible.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Sibling CVE-2026-42016 may appear in the same advisory wave; confirm both IDs and exact fixed builds against JFrog's advisory for your installed build.",
  "firstObservedAt": "2026-09-11T00:00:00.000Z",
  "lastObservedAt": "2026-09-11T19:25:36.274Z",
  "publishedAt": "2026-09-20T18:52:59.848Z",
  "reviewedAt": "2026-09-20T18:52:48.903Z",
  "expiresAt": "2026-09-11T19:25:36.274Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "cisa-kev",
      "label": "CISA KEV catalog entry",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018",
      "sourceType": "government",
      "observedAt": "2026-09-11T19:25:36.274Z"
    },
    {
      "id": "wiz",
      "label": "Wiz in-the-wild Artifactory exploitation write-up",
      "url": "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201",
      "sourceType": "research",
      "observedAt": "2026-09-11T19:25:36.274Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-42018",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42018",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-11T19:25:36.274Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-42018-artifactory-anonymous-token-kev-chain",
      "sourceType": "other_primary",
      "observedAt": "2026-09-11T19:25:36.274Z"
    }
  ],
  "artifacts": [
    {
      "id": "artifactory",
      "artifactClass": "package",
      "ecosystem": "jfrog",
      "name": "JFrog Artifactory",
      "version": ">=0 <7.146.8 (see train-specific floors)",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-11T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-42018 Artifactory anonymous token exposure disclosed / KEV-tracked.",
      "sourceIds": [
        "cisa-kev",
        "wiz",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-11T19:25:36.274Z",
      "eventType": "other",
      "summary": "HOL Guard published operator coverage of the Artifactory anonymous token KEV chain.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Covers the anonymous token / scope chain tracked under CVE-2026-42018 (and related CVE-2026-42016 context); not every Artifactory CVE.",
    "CISA KEV and public in-the-wild reporting elevate urgency; rotate tokens after upgrade if exposure is suspected.",
    "Fixed version list must be verified against JFrog's live advisory for your minor."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-42018-artifactory-anonymous-token-kev-chain/corrections"
}
