Improper Privilege Escalation in Anchore Enterprise User Management API
CVE-2026-63727
8.7HIGH
What is CVE-2026-63727?
A vulnerability exists in Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 that allows an authenticated attacker, with access to the user management API, to exploit insufficient access controls. This enables the attacker to manipulate user permissions, potentially granting excessive access to resources and operations. Notably, while the system-admin role cannot be obtained, a read-only user may be elevated to write access. Users are encouraged to upgrade to versions 5.27.2 or 6.0.1 to mitigate this risk.
Affected Version(s)
Anchore Enterprise 5.11.0
Anchore Enterprise 5.11.0 < 5.27.2
Anchore Enterprise 6.0.0 < 6.0.1
