JFrog Build Readers Access Protected Build Env Secrets
CVE-2026-66018 Published on July 27, 2026
JFrog Artifactory build environment properties exposure
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Vulnerability Analysis
CVE-2026-66018 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-66018 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-66018
Want to know whenever a new CVE is published for JFrog Artifactory? stack.watch will email you.
Affected Versions
jfrog artifactory:- Version 7.146.0 and below 7.146.34 is affected.
- Version 7.161.0 and below 7.161.15 is affected.