Description
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
Published: 2026-07-28
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Anchore Enterprise users who can authenticate to the API may issue a request that alters another user's permissions, allowing the attacker to gain increased access to resources and actions. The flaw resides in the user management API and is classified as a Privilege Escalation vulnerability (CWE-648). It does not expose system‑admin rights but can elevate a read‑only user to write level, increasing the potential damage to confidentiality and integrity of managed artifacts.

Affected Systems

The affected product is Anchore Enterprise. Versions from 5.11.0 through 5.27.1 and the initial 6.0.0 release are vulnerable. The issue is addressed in release 5.27.2 and 6.0.1.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation at this time. The vulnerability is not in the CISA KEV catalog, and the primary attack vector is through an authenticated API call, implying that an attacker must have valid credentials and API access to exploit it. Once activated, the attacker can modify permissions of other users and thereby expand their own authorization scope. The limited scope of the vulnerability to API misuse, combined with the low EPSS, still warrants prompt remediation.

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Anchore Enterprise to version 5.27.2 or later, or to 6.0.1 or later, to apply the official fix.
  • Restrict API access to trusted hosts or networks using firewall or network segmentation to reduce exposure to authenticated attackers.
  • Enforce the principle of least privilege by ensuring API clients only receive the minimal permissions required for their roles and audit role assignments frequently for over‑privileged accounts.

Generated by OpenCVE AI on August 3, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Anchore anchore
CPEs cpe:2.3:a:anchore:anchore:*:*:*:*:enterprise:*:*:*
Vendors & Products Anchore anchore

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Anchore
Anchore anchore Enterprise
Vendors & Products Anchore
Anchore anchore Enterprise

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
Title Anchore Enterprise Privilege Escalation via User Management API
Weaknesses CWE-648
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Anchore Anchore Anchore Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:50:35.603Z

Reserved: 2026-07-17T21:21:58.625Z

Link: CVE-2026-63727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-28T15:17:26.063

Modified: 2026-07-28T16:19:43.127

Link: CVE-2026-63727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses
  • CWE-648

    Incorrect Use of Privileged APIs