Description
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure
Action: Patch
AI Analysis

Impact

Harbor through version 2.15.2 allows a project administrator to exfiltrate the scanner adapter secret by manipulating the q query parameter in the scanner registration API. The vulnerable filtering logic interprets the parameter in a fuzzy manner, letting an adversary submit trial values that are compared against the AccessCredential column. For each request, the response row count indicates whether a partial match exists, enabling the attacker to recover the secret one character at a time. The result is a full disclosure of the scanner’s authentication token, which could be used to perform unauthorized scans or to impersonate the scanner service. This flaw reflects improper information disclosure (CWE‑200).

Affected Systems

The vulnerable product is Harbor, the open source container registry maintained by the Linux Foundation. Versions up to and including 2.15.2 are affected. Administrators of Harbor installations using these releases need to verify the exact version and apply the appropriate fix.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a very low but non-zero probability of exploitation at the time of assessment. The flaw can be exploited remotely by anyone with project administrator privileges, as it operates through an HTTP query parameter. Because the vulnerability requires interaction with the API endpoint, it is not a purely passive weakness. The vulnerability is not currently listed in the CISA KEV catalog, meaning there is no confirmed exploitation in the wild as of this assessment.

Generated by OpenCVE AI on September 18, 2026 at 06:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Harbor to a version that includes the patch for CVE‑2026‑92770.
  • If an upgrade is not immediately possible, block or remove access to the scanner registration API from non‑admin users and enforce strict input validation on the q parameter to prevent fuzzy matching.
  • Monitor Harbor logs for repeated API calls with varying q values that show changing row counts, which could indicate an ongoing credential‑recovery attempt.

Generated by OpenCVE AI on September 18, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Goharbor
Goharbor harbor
Vendors & Products Goharbor
Goharbor harbor

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
Title Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter
First Time appeared Linuxfoundation
Linuxfoundation harbor
Weaknesses CWE-200
CPEs cpe:2.3:a:linuxfoundation:harbor:*:*:*:*:*:*:*:*
Vendors & Products Linuxfoundation
Linuxfoundation harbor
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Goharbor Harbor
Linuxfoundation Harbor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:46:22.699Z

Reserved: 2026-09-16T19:15:38.301Z

Link: CVE-2026-92770

cve-icon Vulnrichment

Updated: 2026-09-21T15:46:20.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:25.597

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-92770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor