CVE-2026-63727
Deferred Deferred - Pending Action

Improper Privilege Escalation in Anchore Enterprise

Vulnerability report for CVE-2026-63727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: VulnCheck

Description

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
anchore enterprise From 5.11.0 (inc) to 5.27.1 (inc)
anchore enterprise 6.0.0
anchore enterprise 5.27.2
anchore enterprise 6.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-648 The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in Anchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0. An authenticated attacker with API access can modify user permissions to gain additional access. For example, a read-only user could be granted write permissions. The system-admin role cannot be granted through this flaw.

Detection Guidance

To detect this vulnerability, check the version of Anchore Enterprise running on your system. If it is between 5.11.0 and 5.27.1 or is version 6.0.0, it is vulnerable. Use commands like 'anchore-enterprise version' or check the deployment logs for version details.

Impact Analysis

An attacker could escalate their privileges to perform unauthorized actions like modifying data, accessing restricted resources, or disrupting operations. This could lead to data breaches, system compromise, or unauthorized changes to configurations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations. It undermines access controls and audit trails, increasing the risk of non-compliance penalties and data exposure.

Mitigation Strategies

Immediately upgrade Anchore Enterprise to version 5.27.2 or 6.0.1, as these versions contain the fix for the privilege escalation vulnerability. Review user permissions and API access logs to identify any unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart