VYPR
Medium severity6.5NVD Advisory· Published Jul 27, 2026· Updated Jul 30, 2026

CVE-2026-66018

CVE-2026-66018

Description

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Jfrog/Artifactory2 versions
    cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*+ 1 more
    • cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*range: >=7.146.0,<7.146.34
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

6