CVE Tools

CVE-2026-66018

JFrog Artifactory build environment properties exposure

Published: Jul 27, 2026Updated: Jul 30, 2026 Sources: CVE List NVDCWE-200

Description

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

In plain language

AI Act now

In JFrog Artifactory, a person who can read an ordinary repository may be able to view secret “build environment” settings from another (protected) build—so if you run Artifactory, you should act fast and upgrade.

Executive summary

CVE-2026-66018 is a JFrog Artifactory information exposure weakness (CWE-200) where users with read permissions to one repository can retrieve environment properties for a protected build in another repository, exposing build environment secrets; exploitation has been reported in the real world.

If affected, business impact
Build secret leakagePrivate credentials exposedSupply-chain data compromiseAccount takeover risk

What to do now

  1. Check your JFrog Artifactory version number (from the application’s “About” page or server logs/config).
  2. If your Artifactory version is older than the fix, upgrade to one of the fixed releases: 7.146.34 or 7.161.15.
  3. Review who has “read” access to repositories: reduce read permissions so fewer users/services can access repositories they shouldn’t.
  4. If you use build environment properties for tokens, passwords, or API keys, rotate those secrets after upgrading (start with any secrets used by builds you consider high value).
Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

jfrog
commercial·USaka artifactory self-hosted, jfrog artifactory

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-66018 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows