CVE-2026-4404: Linuxfoundation Harbor
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Affected products
- Linuxfoundation Harbor: up to and including 2.15.0
Published 2026-03-23. Last modified 2026-08-10.