high · CVSS v3 6.5 · CVSS v4 7.1
CVE-2026-92770
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credenti…
Description
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- 7.1
- EPSS
- —