Improper Privilege Escalation in Anchore Enterprise User Management API
CVE-2026-63727

8.7HIGH

Key Information:

Vendor

Anchore

Vendor
CVE Published:
28 July 2026

What is CVE-2026-63727?

A vulnerability exists in Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 that allows an authenticated attacker, with access to the user management API, to exploit insufficient access controls. This enables the attacker to manipulate user permissions, potentially granting excessive access to resources and operations. Notably, while the system-admin role cannot be obtained, a read-only user may be elevated to write access. Users are encouraged to upgrade to versions 5.27.2 or 6.0.1 to mitigate this risk.

Affected Version(s)

Anchore Enterprise 5.11.0

Anchore Enterprise 5.11.0 < 5.27.2

Anchore Enterprise 6.0.0 < 6.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.