Database/Container, Kubernetes & orchestration
Harbor: Hard-coded default credentials give web UI access to the whole registry
CVE-2026-4404Container, Kubernetes & orchestrationcurated
Impact
Hard-coded default credentials give web UI access to the whole registry
Who can reach it
Unauthenticated network
What to do
Upgrade Harbor immediately and change the default password; treat every hosted image as potentially tampered with and re-verify signatures
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.