cbcvebase.
CVE-2025-62877
published 2026-01-08

CVE-2025-62877: Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive…

PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
37.7th percentile
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.

Affected

6 ranges
VendorProductVersion rangeFixed in
github.comharvester_harvester-installer1.5.0 – 1.5.2
github.comharvester_harvester-installer>= 1.5.0
github.comharvester_harvester-installer1.6.0 – 1.6.1
github.comharvester_harvester-installer>= 1.6.0
suseharvester
suseharvester
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.