{"id":"CVE-2019-16097","aliases":["GHSA-9wvh-ff5f-xjpj","GO-2022-0818"],"url":"https://o3.security/vulnerability/CVE-2019-16097","summary":"Missing Authorization in Harbor","details":"core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.","published":"2019-09-08T16:15:11.820Z","modified":"2026-08-07T14:52:41.674155Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[{"ecosystem":"Go","name":"github.com/goharbor/harbor","fixedVersion":"1.9.0-rc1"}],"fix":{"url":"https://github.com/goharbor/harbor/commit/b6db8a8a106259ec9a2c48be8a380cb3b37cf517","label":"goharbor/harbor@b6db8a8"},"references":[{"type":"ADVISORY","url":"http://www.vmware.com/security/advisories/VMSA-2019-0015.html"},{"type":"ADVISORY","url":"https://github.com/goharbor/harbor/releases/tag/v1.7.6"},{"type":"ADVISORY","url":"https://github.com/goharbor/harbor/releases/tag/v1.8.3"},{"type":"ADVISORY","url":"https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/"},{"type":"FIX","url":"https://github.com/goharbor/harbor/commit/b6db8a8a106259ec9a2c48be8a380cb3b37cf517"},{"type":"FIX","url":"https://github.com/goharbor/harbor/compare/v1.8.2...v1.9.0-rc1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:52:41.674155Z"}}