CVE-2026-4404Disclosure(linuxfoundation / harbor)

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation harbor systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-798CWE-1393

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • harbor

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-23); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Products
harbor

Deep dive

Activity timeline9 mentions / 5d
01122Mentions · 2026-03-23: 2Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-04-01: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-04-01: 2Technical Details · 2026-03-23: 2Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 1Technical Details · 2026-04-01: 203-2303-2503-2603-2704-01
Signal classification2 categories
Disclosure
555.6%
Patch
444.4%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-232
Disclosure2
2026-03-252
Disclosure1Patch1
2026-03-262
Disclosure1Patch1
2026-03-271
Disclosure1
2026-04-012
Patch2
Full discourse9 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    ⚠️ CVE-2026-4404 (GoHarbor Harbor <=2.15.0): Hardcoded creds allow attacker login—full access. Patch: 2.15.1+ https://nvd.nist.gov/vuln/detail/CVE-2026-4404 https://goharbor.io/security/advisories/ https://github.com/goharbor/harbor/security/advisories/GHSA-...

    Post summary

    The note announces CVE‑2026‑4404 with hardcoded credentials that grant full access and provides a specific patch (2.15.1+).

    0002019
    1.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    GoHarbor's Harbor faces a critical 9.4 CVSS flaw (CVE-2026-4404). Default admin passwords allow total registry compromise and image poisoning. Update now. #Harbor #CloudSecurity #ContainerSecurity #CVE #InfoSec #Kubernetes #SupplyChain #DevSecOps https://securityonline.info/harbor-registry-vulnerability-default-credentials-cve-2026-4404/ https://t.co/xofEzm2DsD

    Post summary

    The post highlights a critical CVE with a high CVSS score and urges updating to patch the default-admin-password vulnerability in Harbor.

    00002328
    10.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    GoHarbor の脆弱性 CVE-2026-4404 が FIX:デフォルト認証不備からサプライチェーン攻撃への経路とは? https://iototsecnews.jp/2026/03/25/goharbor-issues-urgent-patch-for-harbor-flaw-allowing-full-registry-compromise/ 今回の Harbor における脆弱性 CVE-2026-4404 は、初期設定時に用意されている管理者パスワードが固定されており、それがそのまま使い続けられてしまう設計上の不備が大きな原因となっています。本来であれば、セットアップの際や初回のログイン時にパスワードの変更を強制する仕組みが必要ですが、このプロセスが省略されていたため、外部から推測されやすい状態が放置されてしまいました。コンテナ・レジストリは開発の基盤となる重要な場所ですので、こうしたデフォルトの設定がそのまま通用してしまうことは、システム全体の安全性を揺るがす大きなリスクに繋がります。ご利用のチームは、ご注意ください。 #CVE20264404 #GoHarbor #Harbor #SupplyChainAttack #Vulnerability

    Post summary

    CVE-2026-4404 in GoHarbor exploits a fixed default admin password, allowing full registry compromise; an urgent patch has been released and systems should be updated immediately.

    01000135
    481 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4404 Hard-Coded Credentials Vulnerability in GoHarbor Harbor Before Version 2.15.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4404

    Post summary

    The message announces a hard‑coded credentials flaw in Harbor (versions before 2.15.0); it provides basic vulnerability details but no exploitation or remediation information.

    0001049
    4.0K followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [CRITICAL] - A critical vulnerability (CVE-2026-4404) has been identified in GoHarbor's Harbor, an open-source OCI-compliant container registry widely used in enterprise cloud-native environments. The vulnerability stems from hardcoded... https://www.enigma-global.com/og/report/cve-2026-4404-critical-hardcoded-default-credentials-in-goharbor-harbor-mn6okmvw-pxi5

    Post summary

    The text announces the discovery of a critical vulnerability (CVE‑2026‑4404) in Harbor due to hardcoded default credentials, with no mention of exploitation, patching, or PoC details.

    0000042
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical default password vulnerability (CVE-2026-4404) affects `Harbor`. Unauthorized web UI access is possible via default credentials. Review and reset all default passwords immediately. #Harbor #ContainerSecurity #CVE https://www.pulsepatch.io/posts/cve-2026-4404-harbor-default-password

    Post summary

    The tweet alerts about a critical default password flaw in Harbor and urges users to reset credentials, but does not provide PoC, exploits, or evidence of active attacks.

    0000048
    3 followersView on X
  • キタきつね@foxbook
    Disclosure

    重大なCVSS 9.4の欠陥により、港湾登録システムが完全な乗っ取りの危険にさらされる Critical 9.4 CVSS Flaw Exposes Harbor Registries to Total Hijack #DailyCyberSecurity (Mar 25) https://securityonline.info/harbor-registry-vulnerability-default-credentials-cve-2026-4404/

    Post summary

    A new CVE-2026-4404 flaw with a CVSS score of 9.4 has been disclosed, exposing Harbor registries to complete hijack, with no PoC, exploit, or patch details mentioned.

    00000249
    4.8K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: #CVE-2026-4404, a critical vulnerability in #GoHarbor Harbor (≤ 2.15.0), involves hard-coded credentials and allows attackers to access the web UI using default passwords. #Patch #Patch #Patch

    Post summary

    The post warns of a critical CVE-2026-4404 vulnerability in Harbor involving hard‑coded credentials and default password access, but provides no PoC, exploit, or patch details.

    00000148
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4404 - Critical Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. https://www.thehackerwire.com/vulnerability/CVE-2026-4404/ https://t.co/oVjOKlUxWM

    Post summary

    The tweet discloses CVE-2026-4404, explaining that hard‑coded credentials in GoHarbor Harbor versions 2.15.0 and earlier allow default password usage for web UI access, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    0000034
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationharbor---

Explore more