CVE detail
CVE-2026-66018
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
8 source links · newest first
l need to shut those paths down first. The fixes shipped in Artifactory 7.161 , covering nine separate vulnerabilities (CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924) ranging from remote code execution and server-side request forgery to path traversal a
newssecurityaffairs.comJul 29, 2026, 11:01 AMs environment properties, and privilege and administrative privilege escalation. The security weaknesses are tracked as CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. Patches for these vulnerabilities were included in Artifactory versions 7.161.15 and 7
newswww.securityweek.comJul 29, 2026, 8:46 AM- JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security
versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre
newswww.theregister.comJul 28, 2026, 10:01 PM - Looks like JFrog's 0-days let OpenAI's models hack Hugging FaceThe Register Security
versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. The Register asked JFrog whether at least some of these were abused by OpenAI’s rogue models to access
newswww.theregister.comJul 28, 2026, 10:01 PM erabilities and specified Artifactory 7.161.15 as the release containing the fixes. The vulnerabilities are tracked as: CVE-2026-65921: Potential path traversal leading to unauthorized file writes CVE-2026-65923: Potential server-side request forgery in Artifactory Ansible repository handling CVE-2026-65924: Server-Side Request Forgery (SSRF) via Terra
newswww.bleepingcomputer.comJul 28, 2026, 8:37 PM- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News
her any of those records correspond to the vulnerabilities used during the evaluation. At least three of those records, CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, credit OpenAI researchers. The records do not map any CVE to the incident, identify the access required before exploitation, or explain why OpenAI refers to one proxy zero-day while
newsthehackernews.comJul 28, 2026, 1:33 PM No excerpt available.
referencedocs.jfrog.comJul 27, 2026, 8:16 PMNo excerpt available.
referencedocs.jfrog.comJul 27, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42017CVSS 8.8 · High
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
- CVE-2024-3505CVSS 4.3 · Medium
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuratio…
- CVE-2026-67529CVSS 4.3 · Medium
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _li…
- CVE-2026-10569CVSS 4.3 · Medium
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is…
- CVE-2026-48499CVSS 9.3 · Critical
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach r…
- CVE-2026-41186CVSS 6.0 · Medium
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authe…