PT-2026-27137 · Harbor · Harbor

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-4404

CVSS v3.1

9.4

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-4404

Affected Products

Harbor