PatchSiren

anchorcms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH anchorcms CVE published 2026-09-10

CVE-2026-88959

Anchor CMS 0.12.7 allows low-privilege users to create administrator accounts or modify existing ones due to a lack of role-based access control in admin user-management endpoints. This vulnerability enables attackers with editor or user roles to POST directly to admin/users/add or admin/users/edit endpoints, potentially gaining full administrative access. Defenders should assess exposure and prioritize r [truncated]