CVE-2026-4404
CRITICAL
9,4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low
Description
AI Translation Available
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
798
Use of Hard-coded Credentials
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Other
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Other
Applicable Platforms
Technologies:
ICS/OT, Mobile
1393
Use of Default Password
IncompleteCommon Consequences
Security Scopes Affected:
Authentication
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
ICS/OT, Not Technology-Specific
https://cwe.mitre.org/data/definitions/1393.html
https://github.com/goharbor/harbor/issues/1937
https://github.com/goharbor/harbor/pull/22751
https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%2…