Vulnerability Details CVE-2026-66018
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 14.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-66018
-
cpe:2.3:a:jfrog:artifactory:7.146.10
-
cpe:2.3:a:jfrog:artifactory:7.146.12
-
cpe:2.3:a:jfrog:artifactory:7.146.13
-
cpe:2.3:a:jfrog:artifactory:7.146.15
-
cpe:2.3:a:jfrog:artifactory:7.146.17
-
cpe:2.3:a:jfrog:artifactory:7.146.22
-
cpe:2.3:a:jfrog:artifactory:7.146.25
-
cpe:2.3:a:jfrog:artifactory:7.146.28
-
cpe:2.3:a:jfrog:artifactory:7.146.29
-
cpe:2.3:a:jfrog:artifactory:7.146.7
-
cpe:2.3:a:jfrog:artifactory:7.161.0