SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63727

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Anchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0 are vulnerable to an improper privilege escalation flaw in the user management API, allowing authenticated attackers to modify user permissions and potentially gain unauthorized access to additional resources. While the system-admin role cannot be granted, a read-only user could be elevated to have write access, posing significant risks to system integrity. Organizations using affected versions should prioritize upgrading to versions 5.27.2 or 6.0.1 to mitigate this high-severity vulnerability.

CVE
CVE-2026-63727
Severity
HIGH
CVSS
8.8
EPSS
0.26%

Original NVD Description

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.