Authorization Bypass in Owen2345 Camaleon CMS Media Crop Handler
CVE-2026-102261
5.3MEDIUM
What is CVE-2026-102261?
A security flaw in Owen2345 Camaleon CMS versions up to 2.9.2 has been identified, specifically within the Media Crop Handler component. The issue arises from an improper manipulation of the saved_avatar argument in the crop function located in the media_controller.rb file. This vulnerability may enable unauthorized users to bypass the necessary authorization, potentially leading to unauthorized access. Remote attacks exploiting this flaw are possible, emphasizing the urgent need for affected users to upgrade to version 2.9.3, which includes a vital security patch (c143e145caa600947e70a240e87f2fed889149d3) to rectify this issue.
Affected Version(s)
Camaleon CMS 2.9.0
Camaleon CMS 2.9.1
Camaleon CMS 2.9.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
7acini (VulDB User)
VulDB Vulnerability Moderation Team
