9.4
CVE-2026-4404
- EPSS 0.49%
- Veröffentlicht 23.03.2026 14:47:13
- Zuletzt bearbeitet 10.08.2026 14:36:20
- CVE-Watchlists
- Unerledigt
Use of hard coded credentials in GoHarbor Harbor
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Harbor Version <= 2.15.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.396 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.4 | 3.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-1393 Use of Default Password
The product uses default passwords for potentially critical functionality.
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://github.com/goharbor/harbor/issues/1937
https://cwe.mitre.org/data/definitions/1393.html
https://github.com/goharbor/harbor/pull/22751
https://www.kb.cert.org/vuls/id/577436
https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%20you%20did%20not%20change%20them%20in%20harbor.yml,%20the%20default%20administrator%20username%20and%20password%20are%20admin%20and%20Harbor12345