CVE-2026-4404
Use of hard coded credentials in GoHarbor Harbor
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Produtos afetados
Harbor · HarborQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://cwe.mitre.org/data/definitions/1393.htmlhttps://github.com/goharbor/harbor/issues/1937https://github.com/goharbor/harbor/pull/22751https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%20you%20did%20not%20change%20them%20in%20harbor.yml,%20the%20default%20administrator%20username%20and%20password%20are%20admin%20and%20Harbor12345https://www.kb.cert.org/vuls/id/577436