CVE-2026-66018
EUVD-2026-4957327.07.2026, 20:16
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jfrog | artifactory | 7.146.0 ≤ 𝑥 < 7.146.34 |
| jfrog | artifactory | 7.161.0 ≤ 𝑥 < 7.161.15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration