CVE-2026-66018
Awaiting Analysis Awaiting Analysis - Queue

Build Readers Access Repository Environment Properties Exposure

Vulnerability report for CVE-2026-66018, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: JFrog

Description

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-28
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows users with read access to a repository to access environment properties of another repository. Specifically, a caller can select a readable repository parameter while retrieving environment properties for a protected build, which may expose build environment secrets.

Impact Analysis

The impact includes confidentiality breaches where sensitive build environment secrets could be exposed. This could lead to unauthorized access to confidential data, but there is no demonstrated impact on integrity or availability of systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive build environment secrets, which may include personal or health data. This could violate GDPR's data protection principles or HIPAA's confidentiality requirements if such data is exposed.

Mitigation Strategies

Restrict repository parameter access to authorized users only. Review and update repository permissions to ensure least privilege. Monitor build environment secrets for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66018. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart