CVE-2026-63727
CVE-2026-63727 is a high-severity vulnerability with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-648.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v4: 8.7
- EPSS exploit prediction: 0% (18th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-648
- Published:
- Last modified:
Description
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
Frequently asked questions
- What is CVE-2026-63727?
- Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
- How severe is CVE-2026-63727?
- CVE-2026-63727 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-63727 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (18th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-63727?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-63727 published?
- CVE-2026-63727 was published on 2026-07-28.
References
- https://docs.anchore.com/5.27/docs/release_notes/enterprise/5272/
- https://www.vulncheck.com/advisories/anchore-enterprise-privilege-escalation-via-user-management-api
Other CWE-648 vulnerabilities
- CVE-2026-41329 — Critical (CVSS 9.9): OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via…
- CVE-2024-8785 — Critical (CVSS 9.8): In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to…
- CVE-2024-11068 — Critical (CVSS 9.8): The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote…
- CVE-2023-4972 — Critical (CVSS 9.8): Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This…
- CVE-2026-41225 — Critical (CVSS 9.1): A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager…
- CVE-2026-41386 — Critical (CVSS 9.1): OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to…