Description
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits a build reader with read access to an ordinary repository to retrieve environment properties for a protected build, revealing build environment secrets that should otherwise remain confidential. This exposure is a direct confidentiality impact and no integrity or availability effects have been demonstrated. It results from improper restriction of read permissions on build environment parameters across repositories.

Affected Systems

JFrog Artifactory is affected; any installation that exposes protected build environment properties to users with ordinary repository read access could be impacted. No specific version information is listed, so all released versions of Artifactory that support build environment properties should be considered potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS score < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation evidence yet. Attackers need only read permission on a non-protected repository; they can then request environment properties for a protected build and obtain secrets. The likely attack vector is remote through the Artifactory API or web interface, and the vulnerability does not require elevated privileges beyond those read rights.

Generated by OpenCVE AI on August 3, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest JFrog Artifactory release that contains the fix for the permission check in build environment property retrieval.
  • Limit ordinary repository read permissions to trusted users and enforce least‑privilege access on build environment parameters.
  • Audit build environment property accesses and review logs for unexpected cross‑repository reads.

Generated by OpenCVE AI on August 3, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Jfrog
Jfrog artifactory
Vendors & Products Jfrog
Jfrog artifactory

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Title JFrog Artifactory build environment properties exposure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jfrog Artifactory
cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-07-27T20:12:51.252Z

Reserved: 2026-07-23T19:59:51.588Z

Link: CVE-2026-66018

cve-icon Vulnrichment

Updated: 2026-07-27T20:12:47.855Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T20:16:42.027

Modified: 2026-07-30T14:46:20.967

Link: CVE-2026-66018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor