CVE-2025-62877
CRITICALSUSE Virtualization (Harvester) <1.5.x,1.6.x - Info Disclosure
Title source: llmDescription
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
5.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-1188
Status
draft
Affected Products (1)
harvester/harvester-installer
Go
Timeline
Published
Jan 08, 2026
Tracked Since
Feb 18, 2026