CyberRota Analysis
AI-GeneratedAnchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0 are vulnerable to an improper privilege escalation flaw in the user management API, allowing authenticated attackers to modify user permissions and potentially gain unauthorized access to additional resources. While the system-admin role cannot be granted, a read-only user could be elevated to have write access, posing significant risks to system integrity. Organizations using affected versions should prioritize upgrading to versions 5.27.2 or 6.0.1 to mitigate this high-severity vulnerability.
Original NVD Description
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.