Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
{
"nvd_published_at": "2026-03-23T15:16:35Z",
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-1393",
"CWE-798"
],
"github_reviewed_at": "2026-03-25T20:10:56Z"
}