CVE-2026-4404 is a critical vulnerability affecting GoHarbor Harbor versions 2.15.0 and below, where hardcoded credentials allow attackers to gain unauthorized web UI access using a default password. With a CVSS score of 9.4 (Critical), this flaw is easily exploitable over the network without requiring privileges or user interaction, leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (e.g., Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has received minimal community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Harbor | Harbor | >= 0.1.0, <= 2.15.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.