Missing Authorization Vulnerability in CamaleonCMS Affected by Arbitrary User ID Access
CVE-2026-56720

5.3MEDIUM

Key Information:

Vendor

Owen2345

Vendor
CVE Published:
11 August 2026

What is CVE-2026-56720?

CamaleonCMS versions 2.9.2 and earlier are susceptible to a missing authorization flaw within the admin users controller. This vulnerability permits any authenticated user to gain unauthorized access to another user's profile data simply by supplying a successive user ID through a GET request to the admin profile endpoint. As a result, sensitive information of any user—including that of administrators—can be disclosed due to the lack of proper role validation checks and absence of ownership verification on the profile action.

Affected Version(s)

CamaleonCMS 0 <= 2.9.2

CamaleonCMS 0 <= 2.9.2

CamaleonCMS ae10da7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saidakbarxon Maxsudxonov
.