Junglewise Threat Intelligence

CVE-2026-66018: JFrog Artifactory information disclosure in environment properties

CVE-2026-66018 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Technologies: JFrog Artifactory Self-Managed. Vendors: JFrog.

Executive brief

JFrog Artifactory, a platform used to manage and store software building blocks, has a security flaw that allows users with limited access to view sensitive information from other projects. An attacker with basic read permissions to one repository could exploit this to steal secrets and environment settings from protected builds in different repositories. This could lead to the exposure of confidential credentials or configuration data used during the software development process.

Technical details

An information disclosure vulnerability (CWE-200) exists in JFrog Artifactory Self-Managed versions. The flaw allows a remote authenticated attacker with 'Build Reader' or general read access to an ordinary repository to select and retrieve repository parameters from other, potentially protected, builds. This occurs during the retrieval of environment properties, leading to the exposure of build environment secrets. The vulnerability is caused by insufficient isolation between repository environment properties. Patches are available in versions 7.146.34 and 7.161.15.

Affected products

  • JFrog Artifactory Self-Managed 7.146.0 to 7.146.33, 7.161.0 to 7.161.14

Timeline

  • 2026-07-27: advisory: JFrog published the security advisory and NVD record.
  • 2026-07-27: patched: Fixed in Artifactory 7.161.15 and 7.146.34.

References

Related threats