Detects Harbor container registry instances running version 2.15.0 or earlier where the default admin password (Harbor12345) has not been changed. Attackers can authenticate with these well-known credentials to gain full admin access — pulling private images, pushing malicious ones, and compromising container supply chains.
Is your app exploitable through CVE-2026-4404?
Scan your domain free