
Two chained CVEs in JFrog Artifactory let an unauthenticated attacker bypass auth, traverse paths, and exfiltrate arbitrary artifacts. All OSS and Enterprise versions below the patched releases were affected. Key findings: - CVE-2026-42018 (auth bypass): POSTing to /access/api/v1/aws/token/ with a trailing slash causes AntPathMatcher to skip AwsTokenAuthenticationFilter entirely. Spring's fallback AnonymousAuthenticationFilter then populates the security context, and the AWS token endpoint mints a valid JWT for the anonymous user, even when anonymous access is disabled. Patch: Artifactory 7.146.8. - CVE-2026-69107 (missing authz + path traversal): The JWT unlocks the deprecated stash API. An attacker POSTs arbitrary repoKey and relativePath values; FileInfo (sha1, sha256, size) is loaded into the session with no ACL check. The stash export then concatenates an attacker-controlled name containing ../ sequences with a base directory, and forceMkdir resolves the traversal, dropping the artifact into the Tomcat web root. - Bug 4 completes the production chain: jf-router does not normalize paths before proxying, so /artifactory/..;/markertag-20260713.141536/sample-v1.0.0 routes through Traefik to Tomcat, which strips the path parameter and serves the file unauthenticated. - The stash oracle is a bonus primitive: a 200 vs error response confirms whether a repo name and artifact path exist, enabling blind enumeration before full exfiltration. #DFIR_Radar
Post summary
The message discloses two chained CVEs in JFrog Artifactory that enable unauthenticated authentication bypass, path traversal, and artifact exfiltration, and it specifies a patch version for remediation.
