CVE-2026-66018: JFrog Artifactory build environment properties exposure
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66018?
The severity of CVE-2026-66018 is rated medium with a score of 6.5.
How does CVE-2026-66018 affect JFrog Artifactory?
CVE-2026-66018 allows build readers to access another repository's environment properties, potentially exposing confidential build environment secrets.
Who is impacted by CVE-2026-66018?
Users with read access to an ordinary repository in JFrog Artifactory are impacted by CVE-2026-66018.
How do I fix CVE-2026-66018?
To fix CVE-2026-66018, restrict access permissions to protect sensitive environment properties in JFrog Artifactory.
What type of vulnerability is CVE-2026-66018 classified as?
CVE-2026-66018 is classified as an information leak vulnerability.