Three JFrog Artifactory Flaws in One KEV Cycle: Authentication Failures in the Build Supply Chain
The repository that every pipeline trusts
Artifactory stores the artifacts that build systems fetch and deploy. A pipeline that pulls a package from it does not re-verify that package's origin; the repository is the trust anchor. Three Artifactory flaws entered the CISA Known Exploited Vulnerabilities catalog in September 2026, and every one of them attacks that trust relationship at the authentication layer.
CISA added CVE-2026-82329 on 2 September 2026, then CVE-2026-42016 and CVE-2026-42018 on 11 September. Due dates fall on 5 September and 25 September respectively.
What each flaw does
CVE-2026-82329 is an improper authentication vulnerability. NVD records a CVSS 3.1 base score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The CISA description states that under default configuration an unauthenticated attacker with network access can obtain administrative privileges.
CVE-2026-42016 is an incorrect authorization vulnerability in Artifactory Self-Hosted before 7.133.11. NVD records a CVSS 3.1 base score of 8.1. The mechanism is specific: the product validates the token's signature and issuer but not the token's scope, so a token issued for a narrow purpose carries more authority than it should.
CVE-2026-42018 is an improper authentication vulnerability. NVD records a CVSS 3.1 base score of 7.5 and describes the outcome as returning an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. The intended configuration makes the system safer; the flaw turns off a control while reporting it as on.
Why build infrastructure deserves a different response than a web server
An Artifactory instance holds private packages, container images, and the configuration that determines where artifacts come from. Administrative access to it allows an attacker to replace an artifact that downstream systems will execute. That path does not require exploiting the build system itself.
The three flaws also compose. CVE-2026-82329 removes the authentication requirement. CVE-2026-42016 widens what a valid token can reach. CVE-2026-42018 leaks a token that should not exist. Public analysis of the September activity has examined Artifactory exploitation in the wild, and the combined picture fits a campaign targeting package infrastructure rather than isolated bug hunting.
Remediation
Patch Artifactory Self-Hosted to 7.133.11 or later for CVE-2026-42016, and to the fixed builds named for the other two in JFrog's security advisories. Confirm the running version rather than the intended one; self-hosted deployments frequently drift from the version on record.
Review configuration with the assumption that defaults are the attack surface. Anonymous access should be disabled where the organization can operate without it, and the state of that setting should be verified after patching rather than assumed.
Rotate credentials and tokens. Any token issued before the fix is a candidate for the scope-validation gap in CVE-2026-42016, and the anonymous-user token exposed through CVE-2026-42018 should be treated as leaked. Audit token creation logs for issuers and scopes that do not match a legitimate pipeline.
Verify artifact integrity for the period before patching. Where signing or checksums exist, compare what the repository serves against what was originally published. Where they do not, that gap is itself a finding worth recording.
References
- NVD, CVE-2026-82329: https://nvd.nist.gov/vuln/detail/CVE-2026-82329
- NVD, CVE-2026-42016: https://nvd.nist.gov/vuln/detail/CVE-2026-42016
- NVD, CVE-2026-42018: https://nvd.nist.gov/vuln/detail/CVE-2026-42018
- JFrog security advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- JFrog Artifactory self-managed release notes: https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- Wiz, Artifactory under attack in the wild: https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-82329: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-42016: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-42018: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018
Top comments (0)