CVE-2026-66018
EUVD-2026-4957327.07.2026, 20:16
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jfrog | artifactory | 7.146.0 ≤ 𝑥 < 7.146.34 | CNA |
| jfrog | artifactory | 7.161.0 ≤ 𝑥 < 7.161.15 | CNA |
Common Weakness Enumeration