9.4

CVE-2026-4404

Medienbericht

Use of hard coded credentials in GoHarbor Harbor

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxfoundationHarbor Version <= 2.15.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.396
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE-1393 Use of Default Password

The product uses default passwords for potentially critical functionality.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
01.04.2026 09:30
https://github.com/goharbor/harbor/issues/1937
Issue Tracking
https://cwe.mitre.org/data/definitions/1393.html
Not Applicable
https://github.com/goharbor/harbor/pull/22751
Issue Tracking
https://www.kb.cert.org/vuls/id/577436
Third Party Advisory
https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%20you%20did%20not%20change%20them%20in%20harbor.yml,%20the%20default%20administrator%20username%20and%20password%20are%20admin%20and%20Harbor12345
Product