« Back to list

Anchore

Anchore Enterprise: vulnerabilities and CVEs

Anchore Enterprise has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-63727High (8.7)0.44%—Jul 28, 2026
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API…
CVE-2026-25076High (8.5)0.32%—Mar 13, 2026
Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able to access the GraphQL API could execute arbitrary SQL instructions…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1005 Data from Local System1
  3. T1098.002 Additional Email Delegate Permissions1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Anchore