PT-2026-27137 · Goharbor · Goharbor

·

CVE-2026-4404

·

Published

2026-03-23

·

Updated

2026-08-17

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions GoHarbor versions prior to 2.15.0
Description The use of hard-coded credentials in GoHarbor allows attackers to use the default password and gain access to the web user interface.
Recommendations Update GoHarbor to version 2.15.0 or later.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2026-4404
CVE-2026-4404
GHSA-HJ7X-HMF2-HC2P
GO-2026-4845
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Goharbor