Role-Based Access Control Flaw in Anchor CMS Admin User Management
CVE-2026-88959
8.7HIGH
What is CVE-2026-88959?
Anchor CMS version 0.12.7 contains a significant flaw in its role-based access control mechanisms. The vulnerability allows authenticated low-privilege users, such as editors or regular users, to access admin user management endpoints. These users can exploit the weakness by sending POST requests to admin/users/add or admin/users/edit, enabling them to create new administrator accounts or modify existing ones. This misconfiguration could potentially give unauthorized users full administrative privileges, posing a considerable risk to the security and integrity of the system.
Affected Version(s)
Anchor CMS 0 <= 0.12.7
