Description
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Published: 2026-01-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6g8q-hp2j-gvwv Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
History

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse harvester
Vendors & Products Suse
Suse harvester

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 12:45:00 +0000

Type Values Removed Values Added
Description Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Title Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-01-08T14:43:34.114Z

Reserved: 2025-10-24T10:34:22.765Z

Link: CVE-2025-62877

cve-icon Vulnrichment

Updated: 2026-01-08T14:41:56.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-08T13:15:41.923

Modified: 2026-01-08T18:08:18.457

Link: CVE-2025-62877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-12T14:38:23Z

Weaknesses