logo

Critical 9.4 CVSS Flaw Exposes Harbor Registries to Total Hijack

ID: a3c781a3-07ee-5602-9215-852e6cecc282

STIX ID: report--a3c781a3-07ee-5602-9215-852e6cecc282

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

CERT/CC warns of CVE-2026-4404: Harbor installs with a default administrative account (username "admin", password "Harbor12345") and does not enforce a password change, allowing remote attackers to gain full administrative access to container registries. Consequences include supply-chain image poisoning, creation of persistent robot/API accounts, data exfiltration via replication, and disabling of signature enforcement or vulnerability scanning; operators are advised to change the harbor_admin_password and upgrade to Harbor 2.15.0 or later where the default-credential issue is addressed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.