Information disclosure in Harbor - #VU153950

 

Information disclosure in Harbor - #VU153950

Published: October 7, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153950
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose scanner credentials.

The vulnerability exists due to a missing restriction on filtering sensitive credential values in scanner_registration.access_cred when handling scanner candidate list requests. A remote user can send repeated queries using the access_cred filter in the q parameter and observe whether a scanner is returned to disclose scanner credentials.

The endpoint requires the Project Admin role or a robot account granted scanner create permission on a project. Recovering a usable credential requires a scanner registration with authentication configured and a credential stored in plain text. Scanner registrations are global and can serve the entire Harbor instance. Registry contents and Harbor accounts are not exposed.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins