What is CVE-2026-66018?
CVE-2026-66018 allows users with 'Build reader' permissions to access environment properties from other repositories. A caller with only read access to a regular repository can expose secrets from protected builds by selecting a readable repository parameter (confidentiality impact). Apply the security update to prevent environment secret leakage.
Azərbaycanca: CVE-2026-66018 boşluğu "Build reader" icazəsinə malik istifadəçilərə başqa repozitoriyaların mühit xüsusiyyətlərini oxumağa imkan verir. Adi repozitoriyaya yalnız oxuma girişi olan şəxs, qorunan "build" prosesinə aid həssas mühit dəyişənlərini ifşa edə bilir (məxfiliyə təsir). Mühit sirlərinizin qorunması üçün bu boşluğu aradan qaldıran təhlükəsizlik yeniləməsini tətbiq edin.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Who can exploit the CVE-2026-66018 vulnerability?
The vulnerability can be exploited by users with 'Build reader' permissions. A caller with only read access to a regular repository can expose sensitive environment variables from protected builds.
What type of data does CVE-2026-66018 expose?
The vulnerability exposes sensitive environment variables from protected builds, meaning environment secrets are leaked, resulting in a confidentiality impact.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.