VYPR

Anchore Enterprise

by Anchore

CVEs (2)

  • CVE-2026-25076HigMar 13, 2026
    risk 0.47cvss 7.3epss 0.00

    Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able to access the GraphQL API could execute arbitrary SQL instructions resulting in modifications to the data contained in the Anchore…

  • CVE-2026-63727HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions…