{"id":"CVE-2026-4404","title":"Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.","summary":"Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.","severity":"critical","cvss":9.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-798","CWE-1393"],"vendor":"linuxfoundation","product":"harbor","affected":["harbor <= 2.15.0"],"published":"2026-03-23","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4404","references":[{"url":"https://cwe.mitre.org/data/definitions/1393.html","label":"cret@cert.org"},{"url":"https://github.com/goharbor/harbor/issues/1937","label":"cret@cert.org"},{"url":"https://github.com/goharbor/harbor/pull/22751","label":"cret@cert.org"},{"url":"https://goharbor.io/docs/1.10/install-config/run-installer-script/#:~:text=If%20you%20did%20not%20change%20them%20in%20harbor.yml,%20the%20default%20administrator%20username%20and%20password%20are%20admin%20and%20Harbor12345","label":"cret@cert.org"},{"url":"https://www.kb.cert.org/vuls/id/577436","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0049,"epssPercentile":0.41098,"ingestedAt":"2026-08-10T14:40:49.750Z","slug":"CVE-2026-4404","body":"## Overview\n\nUse of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.\n\n## Affected\n\n- `harbor <= 2.15.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":51.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}