Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hj7x-hmf2-hc2p | Harbor allows the use of the default password for web UI login |
Tue, 24 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Goharbor
Goharbor harbor |
|
| Vendors & Products |
Goharbor
Goharbor harbor |
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1393 CWE-798 |
|
| Metrics |
cvssV3_1
|
Mon, 23 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | |
| Title | Use of hard coded credentials in GoHarbor Harbor | |
| References |
|
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-03-24T15:25:10.390Z
Reserved: 2026-03-18T19:43:57.063Z
Link: CVE-2026-4404
Updated: 2026-03-24T15:25:10.390Z
Status : Awaiting Analysis
Published: 2026-03-23T15:16:35.403
Modified: 2026-03-24T16:16:36.507
Link: CVE-2026-4404
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:27:58Z
Github GHSA