Vulnerability threat dossier

CVE-2019-16097

linuxfoundationharbor

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

VTP deterministic threat4.5of 100 · CVSS excluded

VTP analyst assessment

Harbor privilege escalation through user creation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence92%
Public exploitation · VTP factUNKNOWN

Assessment

Harbor 1.7.0 through 1.8.2 can allow a non-admin user to create an administrator account through POST /api/users when DB authentication and self-registration are enabled. The supplied CVSS is 6.5, reflecting low-privilege remote exploitation with high integrity impact. Fixed releases are 1.7.6, 1.8.3, and 1.9.0; no exploitation evidence is supplied.

Why it matters

  • Successful exploitation converts ordinary account access into administrative control.
  • Exploitability depends on the DB-authentication and self-registration configuration, providing a clear exposure condition.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The bundle does not establish deployed versions, authentication backend, or self-registration state.

No KEV entry, exploit evidence, or first-party telemetry is supplied; EPSS 0.22443 is predictive only.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Identify Harbor 1.7.0–1.8.2 instances using DB authentication with self-registration enabled.

AI baseline history (1)
  1. BASELINE ASSESSED
    Harbor privilege escalation through user creationgpt-5.6-sol · high
Technical severityMEDIUMCVSS 6.5 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.2298th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2019-16097. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 70/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2019-16097. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 70/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.22; this is predictive context, not exploitation evidence.

  2. 02

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

    05

    Original publications

    Source record

    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score4.5vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction4.49 / 20
    Exploit availability0 / 15
    Source independence0 / 15
    Intelligence recency0 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    6.5 · MEDIUM
    Vector
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
    CWE
    CWE-862
    CPE records
    16
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.