Information disclosure in Harbor - #VU153950
Published: October 7, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose scanner credentials.
The vulnerability exists due to a missing restriction on filtering sensitive credential values in scanner_registration.access_cred when handling scanner candidate list requests. A remote user can send repeated queries using the access_cred filter in the q parameter and observe whether a scanner is returned to disclose scanner credentials.
The endpoint requires the Project Admin role or a robot account granted scanner create permission on a project. Recovering a usable credential requires a scanner registration with authentication configured and a credential stored in plain text. Scanner registrations are global and can serve the entire Harbor instance. Registry contents and Harbor accounts are not exposed.