CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4404

Critical · CVSS 9.4
CVSS
9.4
nvd
EPSS
0.50%
40th pct
KEV
No
Class
oss containerizable
CWE-798, CWE-1393

Description

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Affected packages

Go github.com/goharbor/harbor 0 → ∞

References

Status: profiled · ingested 2026-08-10T18:00:50.000Z