Hard Coded Credentials Vulnerability in GoHarbor Harbor by VMware
CVE-2026-4404
9.4CRITICAL
What is CVE-2026-4404?
The GoHarbor Harbor software, specifically versions up to 2.15.0, contains a vulnerability due to hard coded credentials. This implementation flaw allows attackers to utilize default login details, compromising the security of the web user interface. Attackers can leverage this weakness to gain unauthorized access, potentially exposing sensitive data and functionalities. It's essential for users to update their installations and modify default credentials to mitigate this risk.
Affected Version(s)
Harbor 0.1.0 <= 2.15.0
