CVE-2025-62877
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.52%
- CWE
- CWE-1188
- Published
- 2026-01-08
- Last modified
- 2026-03-12
Affected products
- SUSE harvester
- SUSE harvester
Weakness type
Related vulnerabilities
- CVE-2026-87827 — KGUARD DVR unauthenticated remote command execution vulnerability
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
- CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs
- CVE-2026-75062 — Eval Injection in google/langfun via default lf.query protocol
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-77915 — rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
- CVE-2026-62388 — NLTK before 3.10.0 Insecure Default Configuration in pathsec.py