CVE-2026-66018
JFrog Artifactory build environment properties exposure
Description
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
In plain language
AI Act nowIn JFrog Artifactory, a person who can read an ordinary repository may be able to view secret “build environment” settings from another (protected) build—so if you run Artifactory, you should act fast and upgrade.
CVE-2026-66018 is a JFrog Artifactory information exposure weakness (CWE-200) where users with read permissions to one repository can retrieve environment properties for a protected build in another repository, exposing build environment secrets; exploitation has been reported in the real world.
What to do now
- Check your JFrog Artifactory version number (from the application’s “About” page or server logs/config).
- If your Artifactory version is older than the fix, upgrade to one of the fixed releases: 7.146.34 or 7.161.15.
- Review who has “read” access to repositories: reduce read permissions so fewer users/services can access repositories they shouldn’t.
- If you use build environment properties for tokens, passwords, or API keys, rotate those secrets after upgrading (start with any secrets used by builds you consider high value).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- JFrog Zero-Days Exploited in OpenAI-Hugging Face Hacken-us·SecurityWeek· Exploited Artifactory zero-day
- JFrog tries to spin OpenAI 0-day exploit of its app into a success storyen·Ars Technica (Security)· Exploited Artifactory zero-day
- OpenAI models used Artifactory zero-days to escape to the interneten-us·BleepingComputer· Exploited Artifactory zero-day
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachen·The Hacker News· Exploited Artifactory zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-66018 and every CVE in our database. Create a free account — no credit card required.
Create Free Account