CVE-2026-63727
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management AP
CVSS
8.8
Alto
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Publicado: 28 jul 2026 · Última mod.: 28 jul 2026 · CWE-648
0.3%EPSS · 30 días0.3%
2026-08-192026-09-17
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-7646010.0 CRÍ58.5%
KEV—68Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability2hCVE-2026-544248.4 ALT8.4%
——3An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.73dCVE-2026-95607.8 ALT45.9%
——14Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel56dCVE-2025-545027.5 ALT4.2%
——1Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.65d