PatchSiren

goharbor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH goharbor CVE published 2026-09-16

CVE-2026-92770

CVE-2026-92770 debrief: Harbor through 2.15.2 has a vulnerability where project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts. This vulnerability allows defenders to assess exposure and prioritize remediation, especially in deployments with project administrator access. The vulnerability c [truncated]