PT-2026-27137 · Goharbor · Goharbor

Notnotnotveg

·

Published

2026-03-23

·

Updated

2026-03-27

·

CVE-2026-4404

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions GoHarbor versions prior to 2.15.0
Description The use of hard-coded credentials in GoHarbor allows attackers to use the default password and gain access to the web user interface.
Recommendations Update GoHarbor to version 2.15.0 or later.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-4404
GHSA-HJ7X-HMF2-HC2P
GO-2026-4845
SUSE-SU-2026:1135-1

Affected Products

Goharbor