Authorization Bypass in Owen2345 Camaleon CMS Media Crop Handler
CVE-2026-102261

5.3MEDIUM

Key Information:

Vendor

Owen2345

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102261?

A security flaw in Owen2345 Camaleon CMS versions up to 2.9.2 has been identified, specifically within the Media Crop Handler component. The issue arises from an improper manipulation of the saved_avatar argument in the crop function located in the media_controller.rb file. This vulnerability may enable unauthorized users to bypass the necessary authorization, potentially leading to unauthorized access. Remote attacks exploiting this flaw are possible, emphasizing the urgent need for affected users to upgrade to version 2.9.3, which includes a vital security patch (c143e145caa600947e70a240e87f2fed889149d3) to rectify this issue.

Affected Version(s)

Camaleon CMS 2.9.0

Camaleon CMS 2.9.1

Camaleon CMS 2.9.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

7acini (VulDB User)
VulDB Vulnerability Moderation Team
.