CVE-2026-4404
קריטית 9.4
תיאור (מקור, אנגלית)
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
מדדים
- CVSS 3.1
-
9.4 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-23/9/2026
- CWE
- CWE-798, CWE-1393
מוצרים מושפעים
linuxfoundation: harbor
קישורים
- https://cwe.mitre.org/data/definitions/1393.html Not Applicable
- https://github.com/goharbor/harbor/issues/1937 Issue Tracking
- https://github.com/goharbor/harbor/pull/22751 Issue Tracking
- https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%… Product
- https://www.kb.cert.org/vuls/id/577436 Third Party Advisory