Missing Authorization Vulnerability in CamaleonCMS Affected by Arbitrary User ID Access
CVE-2026-56720
5.3MEDIUM
What is CVE-2026-56720?
CamaleonCMS versions 2.9.2 and earlier are susceptible to a missing authorization flaw within the admin users controller. This vulnerability permits any authenticated user to gain unauthorized access to another user's profile data simply by supplying a successive user ID through a GET request to the admin profile endpoint. As a result, sensitive information of any user—including that of administrators—can be disclosed due to the lack of proper role validation checks and absence of ownership verification on the profile action.
Affected Version(s)
CamaleonCMS 0 <= 2.9.2
CamaleonCMS 0 <= 2.9.2
CamaleonCMS ae10da7
