Improper Certificate Validation in Harbor - #VU153994
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to capture temporary scan robot account credentials.
The vulnerability exists due to improper certificate validation in the jobservice bearer authorization token request when requesting a registry token from Harbor core over HTTPS for a scanner using bearer authorization. A remote attacker can intercept traffic between jobservice and Harbor core and present an arbitrary certificate to capture temporary scan robot account credentials.
Exploitation requires a network position between jobservice and Harbor core. The temporary robot account can read the project being scanned until the scan finishes and Harbor deletes the account.