CVE-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Configurations

No configuration.

History

24 Mar 2026, 16:16

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/577436 -

24 Mar 2026, 15:54

Type Values Removed Values Added
Summary
  • (es) Uso de credenciales codificadas de forma rígida en GoHarbor Harbor versión 2.15.0 y anteriores, permite a los atacantes usar la contraseña predeterminada y obtener acceso a la interfaz de usuario web.

23 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-798
CWE-1393
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.4

23 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 15:16

Updated : 2026-03-24 16:16


NVD link : CVE-2026-4404

Mitre link : CVE-2026-4404

CVE.ORG link : CVE-2026-4404


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials

CWE-1393

Use of Default Password