CVE-2026-63727 Details
Description
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
A privilege escalation vulnerability has been identified in the user management API of Anchore Enterprise, affecting versions 5.11.0 prior to 5.27.2 and 6.0.0 prior to 6.0.1. This vulnerability allows an authenticated attacker with access to the Anchore Enterprise API to modify user permissions, potentially gaining access to additional resources and operations. While the system-admin role cannot be granted, a read-only user could be given write access.
Users can upgrade to Anchore Enterprise versions 5.27.2 or 6.0.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 28, 2026CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.anchore.com/5.27/docs/release_notes/enterprise/5272/ | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/anchore-enterprise-privilege-escalation-via-user-management-api | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-648 | Incorrect Use of Privileged APIs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anchore Enterprise | >= 5.11.0, < 5.27.2 (semver) >= 6.0.0, < 6.0.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | [email protected] |
Volerion