CVE-2025-62877
CRITICALSUSE Virtualization (Harvester) <1.5.x,1.6.x - Info Disclosure
Title source: llmDescription
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
6.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1188
Status
published
Products (3)
harvester/harvester-installer
1.6.0Go
SUSE/harvester
1.5.0
SUSE/harvester
1.6.0
Published
Jan 08, 2026
Tracked Since
Feb 18, 2026