Skip to main content

CVE detail

CVE-2026-66018

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

CVSS 6.5 · MediumBuzz score 38.0

Buzz score

Why this CVE is surfacing

Buzz score total 38.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
8
within the 30d window
Peak daily
4
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • l need to shut those paths down first. The fixes shipped in Artifactory 7.161 , covering nine separate vulnerabilities (CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924) ranging from remote code execution and server-side request forgery to path traversal a

    newssecurityaffairs.comJul 29, 2026, 11:01 AM
  • s environment properties, and privilege and administrative privilege escalation. The security weaknesses are tracked as CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. Patches for these vulnerabilities were included in Artifactory versions 7.161.15 and 7

    newswww.securityweek.comJul 29, 2026, 8:46 AM
  • JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security

    versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre

    newswww.theregister.comJul 28, 2026, 10:01 PM
  • Looks like JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security

    versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. The Register asked JFrog whether at least some of these were abused by OpenAI’s rogue models to access

    newswww.theregister.comJul 28, 2026, 10:01 PM
  • erabilities and specified Artifactory 7.161.15 as the release containing the fixes. The vulnerabilities are tracked as: CVE-2026-65921: Potential path traversal leading to unauthorized file writes CVE-2026-65923: Potential server-side request forgery in Artifactory Ansible repository handling CVE-2026-65924: Server-Side Request Forgery (SSRF) via Terra

    newswww.bleepingcomputer.comJul 28, 2026, 8:37 PM
  • her any of those records correspond to the vulnerabilities used during the evaluation. At least three of those records, CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, credit OpenAI researchers. The records do not map any CVE to the incident, identify the access required before exploitation, or explain why OpenAI refers to one proxy zero-day while

    newsthehackernews.comJul 28, 2026, 1:33 PM
  • No excerpt available.

    referencedocs.jfrog.comJul 27, 2026, 8:16 PM
  • No excerpt available.

    referencedocs.jfrog.comJul 27, 2026, 8:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-42017

    An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.

    CVSS 8.8 · High
    2 mentions
  • CVE-2024-3505

    JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuratio…

    CVSS 4.3 · Medium
  • CVE-2026-67529

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _li…

    CVSS 4.3 · Medium
    6 mentions
  • CVE-2026-10569

    IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is…

    CVSS 4.3 · Medium
    1 mention
  • CVE-2026-48499

    Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach r…

    CVSS 9.3 · Critical
  • CVE-2026-41186

    When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authe…

    CVSS 6.0 · Medium
    4 mentions