FlawAtlas
Search the atlas
CVE-2026-4404 Critical

Use of hard coded credentials in GoHarbor Harbor

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Exploit probability 0.5%
Published March 23, 2026
Required by Not available
Last source change August 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/goharbor/harbor
Go github.com/goharbor/harbor
Unknown Unknown

37 explicit affected versions

Bitnami harbor

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-hj7x-hmf2-hc2p

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

View original source
Open Source Vulnerabilities GO-2026-4845

Harbor allows the use of the default password for web UI login in github.com/goharbor/harbor

View original source
Open Source Vulnerabilities CVE-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

View original source
Open Source Vulnerabilities BIT-harbor-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

View original source

05 / REFERENCES

Further evidence