{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-ABB0491B",
  "slug": "cve-2026-82329-jfrog-artifactory-unauth-admin-default",
  "title": "JFrog Artifactory unauth admin on default config",
  "aliases": [
    "CVE-2026-82329",
    "Artifactory unauth admin default"
  ],
  "summary": "Self-hosted JFrog Artifactory on vulnerable trains can allow unauthenticated administrative access under default configuration conditions. Upgrade to the fixed builds for your train.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Confirm exact fixed build against live JFrog advisory for your minor.",
  "firstObservedAt": "2026-08-28T00:00:00.000Z",
  "lastObservedAt": "2026-08-28T12:00:00.000Z",
  "publishedAt": "2026-09-20T21:41:51.558Z",
  "reviewedAt": "2026-09-20T20:04:33.484Z",
  "expiresAt": "2026-08-28T12:00:00.000Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "nvd",
      "label": "NVD CVE-2026-82329",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-08-28T12:00:00.000Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-82329-jfrog-artifactory-unauth-admin-default",
      "sourceType": "other_primary",
      "observedAt": "2026-08-28T12:00:00.000Z"
    },
    {
      "id": "cveorg",
      "label": "CVE Record CVE-2026-82329",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82329",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-08-28T12:00:00.000Z"
    }
  ],
  "artifacts": [
    {
      "id": "artifactory",
      "artifactClass": "package",
      "ecosystem": "jfrog",
      "name": "JFrog Artifactory",
      "version": "vulnerable trains before 7.111.21 / 7.117.28 / 7.125.20+",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-08-28T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-82329 Artifactory unauth admin on default config disclosed.",
      "sourceIds": [
        "nvd",
        "cveorg"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-08-28T12:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator coverage for CVE-2026-82329.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Distinct from CVE-2026-42018 anonymous-token KEV chain.",
    "Fixed builds from evidence pack.",
    "HOL blog is operator guidance."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-82329-jfrog-artifactory-unauth-admin-default/corrections",
  "heroImageUrl": "https://storage.googleapis.com/inscription-uploads/hol-security-content%2F1789940368419-jfrog-artifactory-campaign-hero.png.png",
  "ogImageUrl": "https://storage.googleapis.com/inscription-uploads/hol-security-content%2F1789940368419-jfrog-artifactory-campaign-hero.png.png",
  "ogTitle": "JFrog Artifactory admin exposure — HOL Guard campaign",
  "ogDescription": "Unauthenticated admin access on default JFrog Artifactory: what HOL Guard verified, which artifacts are affected, and how to contain it.",
  "ogImageAlt": "JFrog Artifactory unauthenticated admin exposure campaign illustration"
}
