Improper Certificate Validation in Harbor - #VU153994

 

Improper Certificate Validation in Harbor - #VU153994

Published: October 8, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153994
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to capture temporary scan robot account credentials.

The vulnerability exists due to improper certificate validation in the jobservice bearer authorization token request when requesting a registry token from Harbor core over HTTPS for a scanner using bearer authorization. A remote attacker can intercept traffic between jobservice and Harbor core and present an arbitrary certificate to capture temporary scan robot account credentials.

Exploitation requires a network position between jobservice and Harbor core. The temporary robot account can read the project being scanned until the scan finishes and Harbor deletes the account.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins