SQL Injection Vulnerability in Anchore Enterprise's GraphQL Reports API
CVE-2026-25076
8.5HIGH
What is CVE-2026-25076?
The Anchore Enterprise platform, prior to version 5.25.1, is susceptible to an SQL injection vulnerability within its GraphQL Reports API. An individual with authenticated access to the GraphQL API can potentially execute arbitrary SQL commands, leading to unauthorized modifications of the Anchore Enterprise database. Organizations utilizing this software should promptly upgrade to version 5.25.1 or later to mitigate this risk. For more information, please visit the official release notes and advisory.
Affected Version(s)
Anchore Enterprise 0 < 5.25.1
