SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66018

MEDIUM · CVSS 6.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Certain build readers can access environment properties from other repositories, allowing unauthorized retrieval of sensitive build environment secrets. This vulnerability primarily impacts organizations using shared repositories where access controls may be misconfigured, potentially leading to confidentiality breaches. Development teams and security personnel should prioritize remediation to safeguard sensitive information and maintain secure build processes.

CVE
CVE-2026-66018
Severity
MEDIUM
CVSS
6.5
EPSS
0.43%

Original NVD Description

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

Related CVEs

Other vulnerabilities affecting the same vendor(s)