GoHarbor Issues Urgent Patch for Harbor Flaw Allowing Full Registry Compromise
ID: 647210d3-64b0-5582-95b6-247e4d3effc3
STIX ID: report--647210d3-64b0-5582-95b6-247e4d3effc3
Feed Name: GBHackers
CVE-2026-4404 is a critical vulnerability in the Harbor container registry caused by hardcoded default administrator credentials and no forced password reset, allowing remote actors to authenticate as admin, alter or inject container images, exfiltrate artifacts, establish persistent access, and enable supply-chain and RCE attacks across CI/CD and connected Kubernetes clusters; operators are advised to immediately change default passwords and set unique credentials in configuration, and a vendor patch is forthcoming to remove or randomize the hardcoded credentials or require password creation during installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
