Not Failing Securely ('Failing Open') in Harbor - #VU153999

 

Not Failing Securely ('Failing Open') in Harbor - #VU153999

Published: October 8, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153999
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-636
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to have requests processed without a determined authentication mode.

The vulnerability exists due to failure to stop request processing after an authentication mode lookup error in Harbor core's request security middleware when reading the configured authentication mode fails. A remote attacker can send requests during such a failure to have requests processed without a determined authentication mode.



Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins