Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, gaining full administrative access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, gaining full administrative access. | |
| Title | Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints | |
| First Time appeared |
Anchorcms
Anchorcms anchor Cms |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:anchorcms:anchor_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Anchorcms
Anchorcms anchor Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T15:44:12.945Z
Reserved: 2026-09-10T15:35:10.247Z
Link: CVE-2026-88959
No data.
Status : Received
Published: 2026-09-10T16:18:12.843
Modified: 2026-09-10T16:18:12.843
Link: CVE-2026-88959
No data.
OpenCVE Enrichment
Updated: 2026-09-10T17:45:16Z
Weaknesses