CVE-2026-66018Active Exploitation(jfrog / artifactory)
MEDIUMCVSS 6.5 · MEDIUMExploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
- Patch jfrog artifactory systems immediately
- Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
4.0/ 10 priority
Sources & remediation
Vendor / third-party advisories
Weakness type (CWE)
CWE-200
Priority
MEDIUM
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- artifactory
Threat summary
- Active exploitation appears in 1 classified signals
- Patch or workaround signal is available
- 1 mentions across 1 observed day
What's happening
- Active exploitation reported across 1 signal
- Patch or workaround mentioned in 1 signal
- 1 total mentions across 1 day
Affected systems
Vendors
Products
artifactory
Deep dive
Activity timeline1 mentions / 1d
Signal classification1 categories
Active Exploitation1100.0%
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | jfrog | artifactory | - | - | - |
