GPU VulnDB

Database/Container, Kubernetes & orchestration

Harbor: fuzzy q filter on scanner credentials lets a project admin extract the adapter secret character by character

CVSS 7.1CVE-2026-92770Container, Kubernetes & orchestrationcurated

Impact

Harbor through 2.15.2 lets the q query parameter apply fuzzy matching to the AccessCredential column of scanner registrations. A project administrator can binary-search the scanner adapter secret one character at a time by watching how many rows come back, recovering the full credential without ever being shown it. That secret authenticates Harbor to the vulnerability scanner adapter, so recovering it gives a tenant-level admin a credential that was meant to be registry-global. In a GPU cloud where Harbor is the shared registry for every tenant's model and CUDA images, the blast radius is the scanner integration for the whole instance, not one project.

Who can reach it

Network access to the Harbor API as an authenticated project administrator - a role routinely handed to tenants who own a namespace of images.

What to do

Upgrade Harbor past 2.15.2 once a fixed release is published and restart the Harbor core service; no fixed version is named in the record. In the meantime rotate the scanner adapter credential and re-register the scanner, and audit which accounts hold project-admin on shared projects. Registry-side change only; running GPU workloads are unaffected, though image pulls pause briefly during the restart.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.